Vulnerability Bulletins

DSA-2869 gnutls26 - incorrect certificate verification


System information

   
Affected software Debian

Description

Nikos Mavrogiannopoulos of Red Hat discovered an X.509 certificateverification issue in GnuTLS, an SSL/TLS library. A certificatevalidation could be reported sucessfully even in cases were an errorwould prevent all verification steps to be performed.

More info:

http://www.debian.org/security/2014/dsa-2869

Standar resources

Property Value
CVE CVE-2014-0092 and DSA-2869.

Version history

Version Comments Date
1.0 Advisory issued 2014-03-05
Ministerio de Defensa
CNI
CCN
CCN-CERT