Blog | G5 Cyber Security

Devil in the details

A German mathematician found a bug in GnuTLS, an open-source library that implements TLS, a protocol that allows client/server applications to communicate in a way that is secure from forgery, eavesdrop or forgery. The identity of a server can be positively established via a chain of X.509 certificates. A root server, usually belonging to a privileged authority such as Thawte, cryptographically signs certificates for other servers (called intermediaries), which in turn can pass on that trust to other servers.”]

Source: https://www.bitdefender.com/blog/hotforsecurity/devil-in-the-details/

Exit mobile version