GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
{ "urgency": "not yet assigned" }