CVE-2014-0092

lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
References
Link Resource
http://gnutls.org/security.html#GNUTLS-SA-2014-2
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00000.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00005.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00007.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00009.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00020.html
http://rhn.redhat.com/errata/RHSA-2014-0246.html
http://rhn.redhat.com/errata/RHSA-2014-0247.html
http://rhn.redhat.com/errata/RHSA-2014-0288.html
http://rhn.redhat.com/errata/RHSA-2014-0339.html
http://secunia.com/advisories/56933 Vendor Advisory
http://secunia.com/advisories/57103
http://secunia.com/advisories/57204 Vendor Advisory
http://secunia.com/advisories/57254
http://secunia.com/advisories/57260
http://secunia.com/advisories/57274
http://secunia.com/advisories/57321
http://www.debian.org/security/2014/dsa-2869
http://www.securityfocus.com/bid/65919
http://www.ubuntu.com/usn/USN-2127-1
https://bugzilla.redhat.com/show_bug.cgi?id=1069865
http://gnutls.org/security.html#GNUTLS-SA-2014-2
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00000.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00005.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00007.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00009.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00020.html
http://rhn.redhat.com/errata/RHSA-2014-0246.html
http://rhn.redhat.com/errata/RHSA-2014-0247.html
http://rhn.redhat.com/errata/RHSA-2014-0288.html
http://rhn.redhat.com/errata/RHSA-2014-0339.html
http://secunia.com/advisories/56933 Vendor Advisory
http://secunia.com/advisories/57103
http://secunia.com/advisories/57204 Vendor Advisory
http://secunia.com/advisories/57254
http://secunia.com/advisories/57260
http://secunia.com/advisories/57274
http://secunia.com/advisories/57321
http://www.debian.org/security/2014/dsa-2869
http://www.securityfocus.com/bid/65919
http://www.ubuntu.com/usn/USN-2127-1
https://bugzilla.redhat.com/show_bug.cgi?id=1069865
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.2.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.2.5:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.2.6:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.2.7:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.2.8:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.2.8.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.2.9:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.2.10:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.1.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.1.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.1.5:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.1.6:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.1.7:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.1.8:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.1.9:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.1.10:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.1.11:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.1.12:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.1.13:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.1.14:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.1.15:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.1.16:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.1.17:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.1.18:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.1.19:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.1.20:*:*:*:*:*:*:*

History

21 Nov 2024, 02:01

Type Values Removed Values Added
References () http://gnutls.org/security.html#GNUTLS-SA-2014-2 - () http://gnutls.org/security.html#GNUTLS-SA-2014-2 -
References () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00000.html - () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00000.html -
References () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00001.html - () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00001.html -
References () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00002.html - () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00002.html -
References () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00003.html - () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00003.html -
References () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00004.html - () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00004.html -
References () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00005.html - () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00005.html -
References () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00006.html - () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00006.html -
References () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00007.html - () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00007.html -
References () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00009.html - () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00009.html -
References () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00020.html - () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00020.html -
References () http://rhn.redhat.com/errata/RHSA-2014-0246.html - () http://rhn.redhat.com/errata/RHSA-2014-0246.html -
References () http://rhn.redhat.com/errata/RHSA-2014-0247.html - () http://rhn.redhat.com/errata/RHSA-2014-0247.html -
References () http://rhn.redhat.com/errata/RHSA-2014-0288.html - () http://rhn.redhat.com/errata/RHSA-2014-0288.html -
References () http://rhn.redhat.com/errata/RHSA-2014-0339.html - () http://rhn.redhat.com/errata/RHSA-2014-0339.html -
References () http://secunia.com/advisories/56933 - Vendor Advisory () http://secunia.com/advisories/56933 - Vendor Advisory
References () http://secunia.com/advisories/57103 - () http://secunia.com/advisories/57103 -
References () http://secunia.com/advisories/57204 - Vendor Advisory () http://secunia.com/advisories/57204 - Vendor Advisory
References () http://secunia.com/advisories/57254 - () http://secunia.com/advisories/57254 -
References () http://secunia.com/advisories/57260 - () http://secunia.com/advisories/57260 -
References () http://secunia.com/advisories/57274 - () http://secunia.com/advisories/57274 -
References () http://secunia.com/advisories/57321 - () http://secunia.com/advisories/57321 -
References () http://www.debian.org/security/2014/dsa-2869 - () http://www.debian.org/security/2014/dsa-2869 -
References () http://www.securityfocus.com/bid/65919 - () http://www.securityfocus.com/bid/65919 -
References () http://www.ubuntu.com/usn/USN-2127-1 - () http://www.ubuntu.com/usn/USN-2127-1 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=1069865 - () https://bugzilla.redhat.com/show_bug.cgi?id=1069865 -

Information

Published : 2014-03-07 00:10

Updated : 2024-11-21 02:01


NVD link : CVE-2014-0092

Mitre link : CVE-2014-0092

CVE.ORG link : CVE-2014-0092


JSON object : View

Products Affected

gnu

  • gnutls
CWE
CWE-310

Cryptographic Issues