Unrated severityNVD Advisory· Published Mar 7, 2014· Updated May 6, 2026
CVE-2014-0092
CVE-2014-0092
Description
lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
26- secunia.com/advisories/56933nvdVendor Advisory
- secunia.com/advisories/57204nvdVendor Advisory
- gnutls.org/security.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2014-03/msg00000.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2014-03/msg00001.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2014-03/msg00002.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2014-03/msg00003.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2014-03/msg00004.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2014-03/msg00005.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2014-03/msg00006.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2014-03/msg00007.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2014-03/msg00009.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2014-03/msg00020.htmlnvd
- rhn.redhat.com/errata/RHSA-2014-0246.htmlnvd
- rhn.redhat.com/errata/RHSA-2014-0247.htmlnvd
- rhn.redhat.com/errata/RHSA-2014-0288.htmlnvd
- rhn.redhat.com/errata/RHSA-2014-0339.htmlnvd
- secunia.com/advisories/57103nvd
- secunia.com/advisories/57254nvd
- secunia.com/advisories/57260nvd
- secunia.com/advisories/57274nvd
- secunia.com/advisories/57321nvd
- www.debian.org/security/2014/dsa-2869nvd
- www.securityfocus.com/bid/65919nvd
- www.ubuntu.com/usn/USN-2127-1nvd
- bugzilla.redhat.com/show_bug.cginvd
News mentions
0No linked articles in our index yet.