Unrated severityNVD Advisory· Published Mar 7, 2014· Updated May 6, 2026
CVE-2014-1959
CVE-2014-1959
Description
lib/x509/verify.c in GnuTLS before 3.1.21 and 3.2.x before 3.2.11 treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to bypass intended restrictions by leveraging a X.509 V1 certificate from a trusted CA to issue new certificates.
Affected products
33cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:*+ 31 more
- cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:*range: <=3.1.20
- cpe:2.3:a:gnu:gnutls:3.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.10:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.11:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.12:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.13:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.14:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.15:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.16:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.17:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.18:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.19:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.9:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.6:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.7:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.8:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.8.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.9:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.gitorious.org/gnutls/gnutls/commit/b1abfe3d182d68539900092eb42fc62cf1bb7e7cnvdExploitPatch
- www.gnutls.org/security.htmlnvdVendor Advisory
- seclists.org/oss-sec/2014/q1/344nvd
- seclists.org/oss-sec/2014/q1/345nvd
- www.debian.org/security/2014/dsa-2866nvd
- www.securityfocus.com/bid/65559nvd
- www.ubuntu.com/usn/USN-2121-1nvd
News mentions
0No linked articles in our index yet.