Lucene search

K
osvGoogleOSV:DLA-180-1
HistoryMar 25, 2015 - 12:00 a.m.

gnutls26 - security update

2015-03-2500:00:00
Google
osv.dev
28

EPSS

0.005

Percentile

75.5%

Multiple vulnerabilities have been discovered in GnuTLS, a library
implementing the TLS and SSL protocols. The Common Vulnerabilities and
Exposures project identifies the following problems:

  • CVE-2014-8155
    Missing date/time checks on CA certificates
  • CVE-2015-0282
    GnuTLS does not verify the RSA PKCS #1 signature algorithm to match
    the signature algorithm in the certificate, leading to a potential
    downgrade to a disallowed algorithm without detecting it.
  • CVE-2015-0294
    GnuTLS does not check whether the two signature algorithms match on
    certificate import.

For Debian 6 Squeeze, these issues have been fixed in gnutls26 version 2.8.6-1+squeeze5