Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-0092
HistoryMar 03, 2014 - 12:00 a.m.

CVE-2014-0092

2014-03-0300:00:00
ubuntu.com
ubuntu.com
14

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

0.075 Low

EPSS

Percentile

94.1%

lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not
properly handle unspecified errors when verifying X.509 certificates from
SSL servers, which allows man-in-the-middle attackers to spoof servers via
a crafted certificate.

OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchgnutls26< 2.8.5-2ubuntu0.5UNKNOWN
ubuntu12.04noarchgnutls26< 2.12.14-5ubuntu3.7UNKNOWN
ubuntu12.10noarchgnutls26< 2.12.14-5ubuntu4.6UNKNOWN
ubuntu13.10noarchgnutls26< 2.12.23-1ubuntu4.2UNKNOWN
ubuntu14.04noarchgnutls26< 2.12.23-12ubuntu2UNKNOWN
ubuntu14.10noarchgnutls26< 2.12.23-12ubuntu2UNKNOWN

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

0.075 Low

EPSS

Percentile

94.1%