CVE-2014-0092

GnuTLS <3.1.22, <3.2.12 - Info Disclosure

Title source: llm
STIX 2.1

Description

lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

References (26)

Core 26
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0288.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0247.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0339.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0246.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/57321
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/57260
Various Sources x_refsource_confirm
http://gnutls.org/security.html#GNUTLS-SA-2014-2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/57274
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/65919
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/57254
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/56933
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1069865
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2127-1
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/57204
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/57103
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2014/dsa-2869

Scores

EPSS 0.0478
EPSS Percentile 89.6%

Details

CWE
CWE-310
Status published
Products (34)
gnu/gnutls 3.2.0
gnu/gnutls 3.2.1
gnu/gnutls 3.2.2
gnu/gnutls 3.2.3
gnu/gnutls 3.2.4
gnu/gnutls 3.2.5
gnu/gnutls 3.2.6
gnu/gnutls 3.2.7
gnu/gnutls 3.2.8
gnu/gnutls 3.2.8.1
... and 24 more
Published Mar 07, 2014
Tracked Since Feb 18, 2026