oss-sec mailing list archives
GnuTLS GNUTLS-SA-2014-2
From: Tomas Hoger <thoger () redhat com>
Date: Mon, 3 Mar 2014 11:05:27 +0100
Hi! New versions of GnuTLS were released today fixing incorrect error handling during X.509 certificate verification. This issue could cause GnuTLS to accept crafted certificate as valid, even if it wasn't issue by a trusted CA. http://lists.gnutls.org/pipermail/gnutls-devel/2014-March/006794.html http://lists.gnutls.org/pipermail/gnutls-devel/2014-March/006795.html http://gnutls.org/security.html#GNUTLS-SA-2014-2 This got CVE-2014-0092 (not mentioned in the gnutls-devel list release announcements, but mentioned on the security page). -- Tomas Hoger / Red Hat Security Response Team
Current thread:
- GnuTLS GNUTLS-SA-2014-2 Tomas Hoger (Mar 03)