CVE Vulnerabilities

CVE-2014-0092

Published: Mar 07, 2014 | Modified: Nov 28, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

Affected Software

Name Vendor Start Version End Version
Gnutls Gnu 3.2.3 3.2.3
Gnutls Gnu 3.2.0 3.2.0
Gnutls Gnu 3.2.1 3.2.1
Gnutls Gnu 3.2.8 3.2.8
Gnutls Gnu 3.2.4 3.2.4
Gnutls Gnu 3.2.9 3.2.9
Gnutls Gnu 3.2.6 3.2.6
Gnutls Gnu 3.2.10 3.2.10
Gnutls Gnu * 3.2.11
Gnutls Gnu 3.2.7 3.2.7
Gnutls Gnu 3.2.2 3.2.2
Gnutls Gnu 3.2.5 3.2.5
Gnutls Gnu 3.2.8.1 3.2.8.1

References