Loading
Generated remediation guidance and an executive summary. No account required.
mod-gnutls does not validate client certificates when "GnuTLSClientVerify require" is set in a directory context, which allows remote attackers to spoof clients via a crafted certificate.
Use CWE-254, Mod Gnutls Project vendor hub and Mod Gnutls product page to widen CVE-2009-5144 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-33307, CVE-2023-25824 and CVE-2026-33308 for nearby disclosures in the same product family.