Description
lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2869-1 | gnutls26 security update |
EUVD |
EUVD-2014-0177 | lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate. |
Ubuntu USN |
USN-2127-1 | GnuTLS vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T09:05:38.662Z
Reserved: 2013-12-03T00:00:00.000Z
Link: CVE-2014-0092
No data.
Status : Modified
Published: 2014-03-07T00:10:53.573
Modified: 2026-05-06T22:30:45.220
Link: CVE-2014-0092
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN