Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Mon, 3 Mar 2014 11:05:27 +0100
From: Tomas Hoger <thoger@...hat.com>
To: oss-security@...ts.openwall.com
Subject: GnuTLS GNUTLS-SA-2014-2

Hi!

New versions of GnuTLS were released today fixing incorrect error
handling during X.509 certificate verification.  This issue could cause
GnuTLS to accept crafted certificate as valid, even if it wasn't issue
by a trusted CA.

http://lists.gnutls.org/pipermail/gnutls-devel/2014-March/006794.html
http://lists.gnutls.org/pipermail/gnutls-devel/2014-March/006795.html
http://gnutls.org/security.html#GNUTLS-SA-2014-2

This got CVE-2014-0092 (not mentioned in the gnutls-devel list release
announcements, but mentioned on the security page).

-- 
Tomas Hoger / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.