Lucene search

K
cve[email protected]CVE-2014-1959
HistoryMar 07, 2014 - 12:10 a.m.

CVE-2014-1959

2014-03-0700:10:57
CWE-264
web.nvd.nist.gov
47
cve-2014-1959
gnutls
x.509 certificates
security vulnerability
nvd
remote attackers
bypass restrictions

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

6.3 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

79.6%

lib/x509/verify.c in GnuTLS before 3.1.21 and 3.2.x before 3.2.11 treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to bypass intended restrictions by leveraging a X.509 V1 certificate from a trusted CA to issue new certificates.

Affected configurations

NVD
Node
gnugnutlsRange3.1.20
OR
gnugnutlsMatch3.1.0
OR
gnugnutlsMatch3.1.1
OR
gnugnutlsMatch3.1.2
OR
gnugnutlsMatch3.1.3
OR
gnugnutlsMatch3.1.4
OR
gnugnutlsMatch3.1.5
OR
gnugnutlsMatch3.1.6
OR
gnugnutlsMatch3.1.7
OR
gnugnutlsMatch3.1.8
OR
gnugnutlsMatch3.1.9
OR
gnugnutlsMatch3.1.10
OR
gnugnutlsMatch3.1.11
OR
gnugnutlsMatch3.1.12
OR
gnugnutlsMatch3.1.13
OR
gnugnutlsMatch3.1.14
OR
gnugnutlsMatch3.1.15
OR
gnugnutlsMatch3.1.16
OR
gnugnutlsMatch3.1.17
OR
gnugnutlsMatch3.1.18
OR
gnugnutlsMatch3.1.19
Node
gnugnutlsRange3.2.10
OR
gnugnutlsMatch3.2.0
OR
gnugnutlsMatch3.2.1
OR
gnugnutlsMatch3.2.2
OR
gnugnutlsMatch3.2.3
OR
gnugnutlsMatch3.2.4
OR
gnugnutlsMatch3.2.5
OR
gnugnutlsMatch3.2.6
OR
gnugnutlsMatch3.2.7
OR
gnugnutlsMatch3.2.8
OR
gnugnutlsMatch3.2.8.1
OR
gnugnutlsMatch3.2.9

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

6.3 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

79.6%