CVE Vulnerabilities

CVE-2014-0092

Published: Mar 07, 2014 | Modified: Nov 28, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
5.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

Affected Software

Name Vendor Start Version End Version
Gnutls Gnu * 3.2.11 (including)
Gnutls Gnu 3.2.0 (including) 3.2.0 (including)
Gnutls Gnu 3.2.1 (including) 3.2.1 (including)
Gnutls Gnu 3.2.2 (including) 3.2.2 (including)
Gnutls Gnu 3.2.3 (including) 3.2.3 (including)
Gnutls Gnu 3.2.4 (including) 3.2.4 (including)
Gnutls Gnu 3.2.5 (including) 3.2.5 (including)
Gnutls Gnu 3.2.6 (including) 3.2.6 (including)
Gnutls Gnu 3.2.7 (including) 3.2.7 (including)
Gnutls Gnu 3.2.8 (including) 3.2.8 (including)
Gnutls Gnu 3.2.8.1 (including) 3.2.8.1 (including)
Gnutls Gnu 3.2.9 (including) 3.2.9 (including)
Gnutls Gnu 3.2.10 (including) 3.2.10 (including)
Red Hat Enterprise Linux 4 Extended Lifecycle Support RedHat gnutls-0:1.0.20-5.el4 *
Red Hat Enterprise Linux 5 RedHat gnutls-0:1.4.1-14.el5_10 *
Red Hat Enterprise Linux 5.3 Long Life RedHat gnutls-0:1.4.1-3.el5_3.6 *
Red Hat Enterprise Linux 5.6 Long Life RedHat gnutls-0:1.4.1-7.el5_6.1 *
Red Hat Enterprise Linux 5.9 Extended Update Support RedHat gnutls-0:1.4.1-10.el5_9.3 *
Red Hat Enterprise Linux 6 RedHat gnutls-0:2.8.5-13.el6_5 *
Red Hat Enterprise Linux 6.2 Advanced Update Support RedHat gnutls-0:2.8.5-4.el6_2.3 *
Red Hat Enterprise Linux 6.3 EUS - Server and Compute Node Only RedHat gnutls-0:2.8.5-7.el6_3.2 *
Red Hat Enterprise Linux 6.4 Extended Update Support RedHat gnutls-0:2.8.5-10.el6_4.3 *
RHEV 3.X Hypervisor and Agents for RHEL-6 RedHat rhev-hypervisor6-0:6.5-20140324.0.el6ev *
Gnutls26 Ubuntu lucid *
Gnutls26 Ubuntu precise *
Gnutls26 Ubuntu quantal *
Gnutls26 Ubuntu saucy *
Gnutls26 Ubuntu trusty *
Gnutls26 Ubuntu utopic *
Gnutls28 Ubuntu precise *
Gnutls28 Ubuntu quantal *
Gnutls28 Ubuntu saucy *
Gnutls28 Ubuntu upstream *

References