Release date:
Updated on:
Affected Systems:
GnuTLS 3.2.12
GnuTLS 3.1.22
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65919
CVE (CAN) ID: CVE-2014-0092
GnuTLS is a function library used to implement TLS encryption.
A security vulnerability exists in versions earlier than GnuTLS 3.1.22 and 3.2.12. The error handling for X.509 Certificate verification is incorrect. You can mark the failure certificate as a valid certificate, this vulnerability allows remote users to bypass certificate verification.
<* Source: vendor
Link: http://www.securitytracker.com/id/1029855
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
GnuTLS
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://gnutls.org
Http://gnutls.org/security.html#GNUTLS-SA-2014-2