CVE-2014-0092
Publication date 3 March 2014
Last updated 24 July 2024
Ubuntu priority
lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
Status
Package | Ubuntu Release | Status |
---|---|---|
gnutls26 | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty |
Fixed 2.12.23-12ubuntu2
|
|
gnutls28 | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
References
Related Ubuntu Security Notices (USN)
- USN-2127-1
- GnuTLS vulnerability
- 4 March 2014