CVE-2014-1959

Publication date 21 February 2014

Last updated 24 July 2024


Ubuntu priority

lib/x509/verify.c in GnuTLS before 3.1.21 and 3.2.x before 3.2.11 treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to bypass intended restrictions by leveraging a X.509 V1 certificate from a trusted CA to issue new certificates.

Read the notes from the security team

Status

Package Ubuntu Release Status
gnutls26 17.04 zesty Not in release
16.10 yakkety Not in release
16.04 LTS xenial Not in release
15.10 wily Not in release
15.04 vivid Not in release
14.10 utopic
Fixed 2.12.23-1ubuntu6
14.04 LTS trusty
Fixed 2.12.23-12ubuntu1
13.10 saucy
Fixed 2.12.23-1ubuntu4.1
12.10 quantal
Fixed 2.12.14-5ubuntu4.5
12.04 LTS precise
Fixed 2.12.14-5ubuntu3.6
10.04 LTS lucid
Not affected
gnutls28 17.04 zesty
Not affected
16.10 yakkety
Not affected
16.04 LTS xenial
Not affected
15.10 wily
Not affected
15.04 vivid
Not affected
14.10 utopic
Not affected
14.04 LTS trusty Not in release
13.10 saucy Ignored end of life
12.10 quantal Ignored end of life
12.04 LTS precise Ignored end of life
10.04 LTS lucid Not in release

Notes


mdeslaur

introduced by: https://www.gitorious.org/gnutls/gnutls/commit/60ee8a0eb9975d123002b1cffbefd60a8cd5fae6

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
gnutls26
gnutls28

References

Related Ubuntu Security Notices (USN)

    • USN-2121-1
    • GnuTLS vulnerability
    • 25 February 2014

Other references