GnuTLS CVE-2014-1959 Certificate Validation Security Bypass Weakness
BID:65559
Info
GnuTLS CVE-2014-1959 Certificate Validation Security Bypass Weakness
| Bugtraq ID: | 65559 |
| Class: | Design Error |
| CVE: |
CVE-2014-1959 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 12 2014 12:00AM |
| Updated: | Jul 15 2015 12:42AM |
| Credit: | Suman Jana |
| Vulnerable: |
Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 AlienVault Open Source SIEM (OSSIM) 3.1 |
| Not Vulnerable: | |
Discussion
GnuTLS CVE-2014-1959 Certificate Validation Security Bypass Weakness
GnuTLS is prone to a security-bypass weakness.
Attackers can exploit this issue to bypass certain security restrictions and perform unauthorized actions. This may aid in further attacks.
GnuTLS 3.1.x and 3.2.x are vulnerable.
GnuTLS is prone to a security-bypass weakness.
Attackers can exploit this issue to bypass certain security restrictions and perform unauthorized actions. This may aid in further attacks.
GnuTLS 3.1.x and 3.2.x are vulnerable.
Exploit / POC
GnuTLS CVE-2014-1959 Certificate Validation Security Bypass Weakness
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
GnuTLS CVE-2014-1959 Certificate Validation Security Bypass Weakness
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
GnuTLS CVE-2014-1959 Certificate Validation Security Bypass Weakness
References:
References: