cbcvebase.
CVE-2014-1959
published 2014-03-07

CVE-2014-1959: lib/x509/verify.c in GnuTLS before 3.1.21 and 3.2.x before 3.2.11 treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to…

medium5.8CVSS 3.1
AVNACMAuNCPIPAN
lib/x509/verify.c in GnuTLS before 3.1.21 and 3.2.x before 3.2.11 treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to bypass intended restrictions by leveraging a X.509 V1 certificate from a trusted CA to issue new certificates.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
debiangnutls28< gnutls28 3.2.11-1 (bookworm)gnutls28 3.2.11-1 (bookworm)
debiangnutls28
gnugnutls<= 2.7.5
gnugnutls<= 3.1.20
gnugnutls<= 3.2.10
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls
gnugnutls

CVSS provenance

nvd5.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM