« List of all CVEs

CVE-2014-8155

Published: 8/14/2015 Last updated: 8/6/2024 Reserved: 10/10/2014

GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-middle attackers to spoof servers via a certificate issued by a CA certificate that is (1) not yet valid or (2) no longer valid.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (5)

conf-gnutls conf-mingw-w64-gnutls-i686 conf-mingw-w64-gnutls-x86_64 conf-srt conf-srt-gnutls

Products affected (2)

Product Vendor Version
n/a n/a < bb2a481778c60f912c363e271ae46b55ff8132db
n/a n/a 6.13

References (16)