Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2008-4989

EPSS 0.39% · P60
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2008-4989

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows man-in-the-middle attackers to insert a spoofed certificate for any Distinguished Name (DN).
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
GnuTLS X.509 'verify.c'证书链验证漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GnuTLS是用于实现TLS加密协议的函数库。 GNU TLS库的X.509证书链验证中存在错误,允许中间人用户使用任意名称并诱骗GNU TLS客户端信任该名称。 漏洞具体存在于x509/verify.c文件的_gnutls_x509_verify_certificate函数中: 1. 用可信任证书列表验证证书列表的最后一个单元。 2. 如果是自签名的话,从列表中删除最后一个单元。 3. 检查证书链确保每个证书都由后一个签名,除了最后一个单元。 如果向列表中添加任意的自签名可信任证书,就不会检查可信任证书
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2008-4989

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-4989

登录查看更多情报信息。

Same Patch Batch · n/a · 2008-11-13 · 38 CVEs total

CVE-2008-5062Mini Web Calendar 'php/cal_pdf.php'目录遍历漏洞
CVE-2008-5053Joomla! com_rssreader组件'admin.rssreader.php'PHP远程代码包含漏洞
CVE-2008-5054Develop It Easy Membership System 多个SQL注入漏洞
CVE-2008-5055ActiveCampaign TrioLive 'department_offline_context.php' SQL注入漏洞
CVE-2008-5056ActiveCampaign TrioLive 'department_offline_context.php' 跨站脚本攻击漏洞
CVE-2008-5057Dizi Portali 'film.asp'SQL注入漏洞
CVE-2008-5058Pre Simple CMS ’siteadmin/loginsucess.php'SQL注入漏洞
CVE-2008-5059ModernBill 'index.php' 跨站脚本攻击漏洞
CVE-2008-5060ModernBill 多个PHP远程文件包含漏洞
CVE-2008-5061Mini Web Calendar 'php/cal_default.php'跨站脚本攻击漏洞
CVE-2008-5052Mozilla多个产品JavaScript引擎属性值函数拒绝服务攻击漏洞
CVE-2008-5063OTManager 'Admin/ADM_Pagina.php' PHP代码注入漏洞
CVE-2008-5046Mole Group Pizza Script 'index.php' SQL注入漏洞
CVE-2008-5047Mole Group Rental Script 'login.php' SQL注入漏洞
CVE-2008-5048Anti-Trojan Elite IOCTL 'Atepmon.sys'拒绝服务或执行任意代码漏洞
CVE-2008-5049Anti-Keylogger Elite IOCTL 'AKEProtect.sys'请求本地权限提升漏洞
CVE-2008-5050ClamAV ’get_unicode_name‘函数单字节堆溢出漏洞
CVE-2008-5051Joomla! JooBlog组件'index.php'SQL注入漏洞
CVE-2008-5045Network-Client FTP Now堆缓冲区溢出漏洞
CVE-2008-5015Mozilla Firefox/Thunderbird/SeaMonkey chrome特权本地文件权限提升漏洞

Showing top 20 of 38 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2008-4989

No comments yet


Leave a comment