Date: Mon, 3 Mar 2014 11:05:27 +0100 From: Tomas Hoger <thoger@...hat.com> To: oss-security@...ts.openwall.com Subject: GnuTLS GNUTLS-SA-2014-2 Hi! New versions of GnuTLS were released today fixing incorrect error handling during X.509 certificate verification. This issue could cause GnuTLS to accept crafted certificate as valid, even if it wasn't issue by a trusted CA. http://lists.gnutls.org/pipermail/gnutls-devel/2014-March/006794.html http://lists.gnutls.org/pipermail/gnutls-devel/2014-March/006795.html http://gnutls.org/security.html#GNUTLS-SA-2014-2 This got CVE-2014-0092 (not mentioned in the gnutls-devel list release announcements, but mentioned on the security page). -- Tomas Hoger / Red Hat Security Response Team
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Powered by Openwall GNU/*/Linux - Powered by OpenVZ