CVE-2014-8155
published 2015-08-14CVE-2014-8155: GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-middle attackers to spoof servers via a…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.05%
60.6th percentile
GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-middle attackers to spoof servers via a certificate issued by a CA certificate that is (1) not yet valid or (2) no longer valid.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnutls28 | — | — |
| gnu | gnutls | <= 2.9.9 | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q3j8-fx5r-2c6f: GnuTLS before 2
ghsa_unreviewed·2022-05-14
CVE-2014-8155 [MEDIUM] GHSA-q3j8-fx5r-2c6f: GnuTLS before 2
GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-middle attackers to spoof servers via a certificate issued by a CA certificate that is (1) not yet valid or (2) no longer valid.
OSV
gnutls26, gnutls28 vulnerabilities
osv·2015-03-23·CVSS 4.3
CVE-2014-8155 [MEDIUM] gnutls26, gnutls28 vulnerabilities
gnutls26, gnutls28 vulnerabilities
It was discovered that GnuTLS did not perform date and time checks on
CA certificates, contrary to expectations. This issue only affected
Ubuntu 10.04 LTS. (CVE-2014-8155)
Nikos Mavrogiannopoulos discovered that GnuTLS incorrectly verified that
signature algorithms matched. A remote attacker could possibly use this
issue to downgrade to a disallowed algorithm. This issue only affected
Ubuntu 10.04 LTS, Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-0282)
It was discovered that GnuTLS incorrectly verified certificate algorithms.
A remote attacker could possibly use this issue to downgrade to a
disallowed algorithm. (CVE-2015-0294)
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2015-03-23·CVSS 4.3
CVE-2014-8155 [MEDIUM] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
It was discovered that GnuTLS did not perform date and time checks on
CA certificates, contrary to expectations. This issue only affected
Ubuntu 10.04 LTS. (CVE-2014-8155)
Nikos Mavrogiannopoulos discovered that GnuTLS incorrectly verified that
signature algorithms matched. A remote attacker could possibly use this
issue to downgrade to a disallowed algorithm. This issue only affected
Ubuntu 10.04 LTS, Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-0282)
It was discovered that GnuTLS incorrectly verified certificate algorithms.
A remote attacker could possibly use this issue to downgrade to a
disallowed algorithm. (CVE-2015-0294)
Instructions: In general, a standard system update will make all the n
Debian
CVE-2014-8155: gnutls28 - GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA c...
vendor_debian·2014·CVSS 4.3
CVE-2014-8155 [MEDIUM] CVE-2014-8155: gnutls28 - GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA c...
GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-middle attackers to spoof servers via a certificate issued by a CA certificate that is (1) not yet valid or (2) no longer valid.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Red Hat
gnutls: gnutls does not perform date/time checks on CA certificates
vendor_redhat·2010-03-14·CVSS 4.3
CVE-2014-8155 [MEDIUM] CWE-325 gnutls: gnutls does not perform date/time checks on CA certificates
gnutls: gnutls does not perform date/time checks on CA certificates
GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-middle attackers to spoof servers via a certificate issued by a CA certificate that is (1) not yet valid or (2) no longer valid.
It was found that GnuTLS did not check activation and expiration dates of CA certificates. This could cause an application using GnuTLS to incorrectly accept a certificate as valid when its issuing CA is already expired.
Statement: This issue did not affect the version of gnutls package as shipped with Red Hat Enterprise Linux 7.
This issue affects the version of gnutls as shipped with Red Hat Enterprise Linux 5. Red Hat Enterprise Linux 5 is now in Extended Life Cycle phase of
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2015-1457.htmlhttp://www.securityfocus.com/bid/73317https://gitlab.com/gnutls/gnutls/commit/897cbce62c0263a498088ac3e465aa5f05f8719chttps://support.f5.com/csp/article/K53330207http://rhn.redhat.com/errata/RHSA-2015-1457.htmlhttp://www.securityfocus.com/bid/73317https://gitlab.com/gnutls/gnutls/commit/897cbce62c0263a498088ac3e465aa5f05f8719chttps://support.f5.com/csp/article/K53330207
2015-08-14
Published