cbcvebase.
CVE-2014-1959
published 2014-03-07

CVE-2014-1959: lib/x509/verify.c in GnuTLS before 3.1.21 and 3.2.x before 3.2.11 treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to…

PriorityP431medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
3.42%
87.6th percentile
lib/x509/verify.c in GnuTLS before 3.1.21 and 3.2.x before 3.2.11 treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to bypass intended restrictions by leveraging a X.509 V1 certificate from a trusted CA to issue new certificates.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
debiangnutls28< gnutls28 3.2.11-1 (bookworm)gnutls28 3.2.11-1 (bookworm)
debiangnutls28
gnugnutls<= 2.7.5
gnugnutls<= 3.1.20
gnugnutls<= 3.2.10
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls

CVSS provenance

nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.