CVE-2015-0294
published 2020-01-27CVE-2015-0294: GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
1.59%
72.9th percentile
GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | gnutls28 | < gnutls28 3.3.8-6 (bookworm) | gnutls28 3.3.8-6 (bookworm) |
| gnu | gnutls | < 3.3.13 | 3.3.13 |
| gnutls | gnutls | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xqm3-jfj9-8pf2: GnuTLS before 3
ghsa_unreviewed·2022-05-24
CVE-2015-0294 [HIGH] CWE-295 GHSA-xqm3-jfj9-8pf2: GnuTLS before 3
GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
OSV
CVE-2015-0294: GnuTLS before 3
osv·2020-01-27·CVSS 7.5
CVE-2015-0294 [HIGH] CVE-2015-0294: GnuTLS before 3
GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
OSV
gnutls26, gnutls28 vulnerabilities
osv·2015-03-23·CVSS 4.3
CVE-2014-8155 [MEDIUM] gnutls26, gnutls28 vulnerabilities
gnutls26, gnutls28 vulnerabilities
It was discovered that GnuTLS did not perform date and time checks on
CA certificates, contrary to expectations. This issue only affected
Ubuntu 10.04 LTS. (CVE-2014-8155)
Nikos Mavrogiannopoulos discovered that GnuTLS incorrectly verified that
signature algorithms matched. A remote attacker could possibly use this
issue to downgrade to a disallowed algorithm. This issue only affected
Ubuntu 10.04 LTS, Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-0282)
It was discovered that GnuTLS incorrectly verified certificate algorithms.
A remote attacker could possibly use this issue to downgrade to a
disallowed algorithm. (CVE-2015-0294)
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2015-03-23·CVSS 4.3
CVE-2014-8155 [MEDIUM] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
It was discovered that GnuTLS did not perform date and time checks on
CA certificates, contrary to expectations. This issue only affected
Ubuntu 10.04 LTS. (CVE-2014-8155)
Nikos Mavrogiannopoulos discovered that GnuTLS incorrectly verified that
signature algorithms matched. A remote attacker could possibly use this
issue to downgrade to a disallowed algorithm. This issue only affected
Ubuntu 10.04 LTS, Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-0282)
It was discovered that GnuTLS incorrectly verified certificate algorithms.
A remote attacker could possibly use this issue to downgrade to a
disallowed algorithm. (CVE-2015-0294)
Instructions: In general, a standard system update will make all the n
Red Hat
gnutls: certificate algorithm consistency checking issue
vendor_redhat·2015-02-27·CVSS 7.5
CVE-2015-0294 [HIGH] CWE-295 gnutls: certificate algorithm consistency checking issue
gnutls: certificate algorithm consistency checking issue
GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
It was discovered that GnuTLS did not check if all sections of X.509 certificates indicate the same signature algorithm. This flaw, in combination with a different flaw, could possibly lead to a bypass of the certificate signature check.
Statement: This issue affects the version of gnutls package as shipped with Red Hat Enterprise Linux 7. Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates.
This issue affects the version of gnutls package as shipped with Red Hat Enterprise Linux 5. Red Hat Enterprise Linux 5 is now in Extended Life C
Debian
CVE-2015-0294: gnutls28 - GnuTLS before 3.3.13 does not validate that the signature algorithms match when ...
vendor_debian·2015·CVSS 7.5
CVE-2015-0294 [HIGH] CVE-2015-0294: gnutls28 - GnuTLS before 3.3.13 does not validate that the signature algorithms match when ...
GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
Scope: local
bookworm: resolved (fixed in 3.3.8-6)
bullseye: resolved (fixed in 3.3.8-6)
forky: resolved (fixed in 3.3.8-6)
sid: resolved (fixed in 3.3.8-6)
trixie: resolved (fixed in 3.3.8-6)
No detection rules found.
No public exploits indexed.
http://www.debian.org/security/2015/dsa-3191https://bugzilla.redhat.com/show_bug.cgi?id=1196323https://gitlab.com/gnutls/gnutls/commit/6e76e9b9fa845b76b0b9a45f05f4b54a052578ffhttp://www.debian.org/security/2015/dsa-3191https://bugzilla.redhat.com/show_bug.cgi?id=1196323https://gitlab.com/gnutls/gnutls/commit/6e76e9b9fa845b76b0b9a45f05f4b54a052578ff
2020-01-27
Published