A critical vulnerability in the GnuTLS library on Ubuntu allows signature forgery without the private key. Users should update configurations and audit systems.
The GnuTLS library did not sufficiently check the padding of PKCS #1 v1.5 signatures if the exponent of the public key is 3 (which is widely used for CAs)