CVE-2014-8155: Medium severity gnutls vulnerability
Published Aug 14, 2015
·Updated
GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-middle attackers to spoof servers via a certificate issued by a CA certificate that is (1) not yet valid or (2) no longer valid.
Affected Software
1 affected component
GNU GnuTLS<=2.9.9
Event History
Aug 14, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8155?
CVE-2014-8155 is classified as a medium severity vulnerability due to the potential for man-in-the-middle attacks.
2
How do I fix CVE-2014-8155?
To fix CVE-2014-8155, upgrade GnuTLS to version 2.9.10 or later.
3
What exploit does CVE-2014-8155 enable?
CVE-2014-8155 allows attackers to spoof servers by using certificates from CA certificates that are not yet valid or have expired.
4
Which versions of GnuTLS are affected by CVE-2014-8155?
CVE-2014-8155 affects GnuTLS versions prior to 2.9.10.
5
What impact does CVE-2014-8155 have on server communication?
CVE-2014-8155 compromises the integrity of server communication by allowing unauthenticated access via invalid certificates.