cbcvebase.
CVE-2014-0092
published 2014-03-07

CVE-2014-0092: lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL…

medium5.8CVSS 3.1
AVNACMAuNCPIPAN
lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debiangnutls28< gnutls28 3.2.11-2 (bookworm)gnutls28 3.2.11-2 (bookworm)
gnugnutls<= 3.2.11
gnugnutls<= 3.1.21
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls

CVSS provenance

nvd5.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM