Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-0294

Опубликовано: 27 фев. 2015
Источник: redhat
CVSS2: 4.3

Описание

GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.

It was discovered that GnuTLS did not check if all sections of X.509 certificates indicate the same signature algorithm. This flaw, in combination with a different flaw, could possibly lead to a bypass of the certificate signature check.

Отчет

This issue affects the version of gnutls package as shipped with Red Hat Enterprise Linux 7. Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. This issue affects the version of gnutls package as shipped with Red Hat Enterprise Linux 5. Red Hat Enterprise Linux 5 is now in Extended Life Cycle phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gnutlsWill not fix
Red Hat Enterprise Linux 7gnutlsWill not fix
Red Hat Enterprise Virtualization 3mingw-virt-viewerWill not fix
Red Hat Enterprise Linux 6gnutlsFixedRHSA-2015:145721.07.2015

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=1196323gnutls: certificate algorithm consistency checking issue

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.

CVSS3: 7.5
nvd
почти 6 лет назад

GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.

CVSS3: 7.5
debian
почти 6 лет назад

GnuTLS before 3.3.13 does not validate that the signature algorithms m ...

suse-cvrf
больше 10 лет назад

Security update for gnutls

CVSS3: 7.5
github
больше 3 лет назад

GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.

4.3 Medium

CVSS2