oss-sec mailing list archives

GnuTLS GNUTLS-SA-2014-2


From: Tomas Hoger <thoger () redhat com>
Date: Mon, 3 Mar 2014 11:05:27 +0100

Hi!

New versions of GnuTLS were released today fixing incorrect error
handling during X.509 certificate verification.  This issue could cause
GnuTLS to accept crafted certificate as valid, even if it wasn't issue
by a trusted CA.

http://lists.gnutls.org/pipermail/gnutls-devel/2014-March/006794.html
http://lists.gnutls.org/pipermail/gnutls-devel/2014-March/006795.html
http://gnutls.org/security.html#GNUTLS-SA-2014-2

This got CVE-2014-0092 (not mentioned in the gnutls-devel list release
announcements, but mentioned on the security page).

-- 
Tomas Hoger / Red Hat Security Response Team


Current thread: