Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [day] [month] [year] [list]
Date: Mon, 3 Mar 2014 11:05:27 +0100
From: Tomas Hoger <thoger@...hat.com>
To: oss-security@...ts.openwall.com
Subject: GnuTLS GNUTLS-SA-2014-2

Hi!

New versions of GnuTLS were released today fixing incorrect error
handling during X.509 certificate verification.  This issue could cause
GnuTLS to accept crafted certificate as valid, even if it wasn't issue
by a trusted CA.

http://lists.gnutls.org/pipermail/gnutls-devel/2014-March/006794.html
http://lists.gnutls.org/pipermail/gnutls-devel/2014-March/006795.html
http://gnutls.org/security.html#GNUTLS-SA-2014-2

This got CVE-2014-0092 (not mentioned in the gnutls-devel list release
announcements, but mentioned on the security page).

-- 
Tomas Hoger / Red Hat Security Response Team

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ