cbcvebase.
CVE-2014-0092
published 2014-03-07

CVE-2014-0092: lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL…

PriorityP339medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
29.96%
98.0th percentile
lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debiangnutls28< gnutls28 3.2.11-2 (bookworm)gnutls28 3.2.11-2 (bookworm)
gnugnutls<= 3.2.11
gnugnutls<= 3.1.21
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls

CVSS provenance

nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.