CVE-2015-0294

Published: 01 March 2015

GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.

Priority

Low

CVSS 3 base score: 7.5

Status

Package Release Status
gnutls26
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr)
Released (2.12.23-12ubuntu2.2)
Patches:
Upstream: https://gitlab.com/gnutls/gnutls/commit/2458d6d158fd523418e331e50abb35cd334bb795
gnutls28
Launchpad, Ubuntu, Debian
Upstream
Released (3.3.8-6,3.3.13)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (3.3.8-3ubuntu3)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (3.3.8-3ubuntu3)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was needed)
Patches:
Upstream: https://gitlab.com/gnutls/gnutls/commit/6e76e9b9fa845b76b0b9a45f05f4b54a052578ff (gnutls_3_3_13)
Upstream: https://gitlab.com/gnutls/gnutls/commit/ca35341243dc2ba13cd703d25becea5da293bc35 (test)