CVE-2014-8155
Publication date 31 December 2014
Last updated 24 July 2024
Ubuntu priority
Description
GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-middle attackers to spoof servers via a certificate issued by a CA certificate that is (1) not yet valid or (2) no longer valid.
Status
Package | Ubuntu Release | Status |
---|---|---|
gnutls26 | ||
14.04 LTS trusty |
Not affected
|
|
gnutls28 | ||
14.04 LTS trusty | Not in release | |
Notes
References
Related Ubuntu Security Notices (USN)
- USN-2540-1
- GnuTLS vulnerabilities
- 23 March 2015