CVE Vulnerabilities

CVE-2014-0092

Published: Mar 07, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
5.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

Affected Software

NameVendorStart VersionEnd Version
GnutlsGnu*3.2.11 (including)
GnutlsGnu3.2.0 (including)3.2.0 (including)
GnutlsGnu3.2.1 (including)3.2.1 (including)
GnutlsGnu3.2.2 (including)3.2.2 (including)
GnutlsGnu3.2.3 (including)3.2.3 (including)
GnutlsGnu3.2.4 (including)3.2.4 (including)
GnutlsGnu3.2.5 (including)3.2.5 (including)
GnutlsGnu3.2.6 (including)3.2.6 (including)
GnutlsGnu3.2.7 (including)3.2.7 (including)
GnutlsGnu3.2.8 (including)3.2.8 (including)
GnutlsGnu3.2.8.1 (including)3.2.8.1 (including)
GnutlsGnu3.2.9 (including)3.2.9 (including)
GnutlsGnu3.2.10 (including)3.2.10 (including)
Red Hat Enterprise Linux 4 Extended Lifecycle SupportRedHatgnutls-0:1.0.20-5.el4*
Red Hat Enterprise Linux 5RedHatgnutls-0:1.4.1-14.el5_10*
Red Hat Enterprise Linux 5.3 Long LifeRedHatgnutls-0:1.4.1-3.el5_3.6*
Red Hat Enterprise Linux 5.6 Long LifeRedHatgnutls-0:1.4.1-7.el5_6.1*
Red Hat Enterprise Linux 5.9 Extended Update SupportRedHatgnutls-0:1.4.1-10.el5_9.3*
Red Hat Enterprise Linux 6RedHatgnutls-0:2.8.5-13.el6_5*
Red Hat Enterprise Linux 6.2 Advanced Update SupportRedHatgnutls-0:2.8.5-4.el6_2.3*
Red Hat Enterprise Linux 6.3 EUS - Server and Compute Node OnlyRedHatgnutls-0:2.8.5-7.el6_3.2*
Red Hat Enterprise Linux 6.4 Extended Update SupportRedHatgnutls-0:2.8.5-10.el6_4.3*
RHEV 3.X Hypervisor and Agents for RHEL-6RedHatrhev-hypervisor6-0:6.5-20140324.0.el6ev*
Gnutls26Ubuntuesm-infra-legacy/trusty*
Gnutls26Ubuntulucid*
Gnutls26Ubuntuprecise*
Gnutls26Ubuntuquantal*
Gnutls26Ubuntusaucy*
Gnutls26Ubuntutrusty*
Gnutls26Ubuntutrusty/esm*
Gnutls26Ubuntuutopic*
Gnutls28Ubuntuprecise*
Gnutls28Ubuntuquantal*
Gnutls28Ubuntusaucy*
Gnutls28Ubuntuupstream*

References