Upstream information

CVE-2014-1959 at MITRE

Description

lib/x509/verify.c in GnuTLS before 3.1.21 and 3.2.x before 3.2.11 treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to bypass intended restrictions by leveraging a X.509 V1 certificate from a trusted CA to issue new certificates.

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 5.8
Vector AV:N/AC:M/Au:N/C:P/I:P/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact None
SUSE Bugzilla entries: 863989 [RESOLVED / FIXED], 865993 [RESOLVED / FIXED]

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 12
  • gnutls >= 3.2.15-1.8
  • libgnutls28 >= 3.2.15-1.8
  • libgnutls28-32bit >= 3.2.15-1.8
Patchnames:
SUSE Linux Enterprise Desktop 12 GA gnutls
SUSE Linux Enterprise Desktop 12 SP1
  • gnutls >= 3.2.15-11.1
  • libgnutls28 >= 3.2.15-11.1
  • libgnutls28-32bit >= 3.2.15-11.1
Patchnames:
SUSE Linux Enterprise Desktop 12 SP1 GA gnutls
SUSE Linux Enterprise Desktop 12 SP2
  • gnutls >= 3.2.15-11.1
  • libgnutls28 >= 3.2.15-11.1
  • libgnutls28-32bit >= 3.2.15-11.1
Patchnames:
SUSE Linux Enterprise Desktop 12 SP2 GA gnutls
SUSE Linux Enterprise Desktop 12 SP3
  • gnutls >= 3.3.27-1.10
  • libgnutls28 >= 3.3.27-1.10
  • libgnutls28-32bit >= 3.3.27-1.10
Patchnames:
SUSE Linux Enterprise Desktop 12 SP3 GA gnutls
SUSE Linux Enterprise Module for Basesystem 15
  • gnutls >= 3.6.2-4.15
  • libgnutls-devel >= 3.6.2-4.15
  • libgnutls30 >= 3.6.2-4.15
  • libgnutlsxx-devel >= 3.6.2-4.15
  • libgnutlsxx28 >= 3.6.2-4.15
Patchnames:
SUSE Linux Enterprise Module for Basesystem 15 GA gnutls
SUSE Linux Enterprise Module for Desktop Applications 15
  • libgnutls30-32bit >= 3.6.2-4.15
Patchnames:
SUSE Linux Enterprise Module for Desktop Applications 15 GA libgnutls30-32bit
SUSE Linux Enterprise Server 12
  • gnutls >= 3.2.15-1.8
  • libgnutls-openssl27 >= 3.2.15-1.8
  • libgnutls28 >= 3.2.15-1.8
  • libgnutls28-32bit >= 3.2.15-1.8
Patchnames:
SUSE Linux Enterprise Server 12 GA gnutls
SUSE Linux Enterprise Server 12 SP1
  • gnutls >= 3.2.15-11.1
  • libgnutls-openssl27 >= 3.2.15-11.1
  • libgnutls28 >= 3.2.15-11.1
  • libgnutls28-32bit >= 3.2.15-11.1
Patchnames:
SUSE Linux Enterprise Server 12 SP1 GA gnutls
SUSE Linux Enterprise Server 12 SP2
  • gnutls >= 3.2.15-11.1
  • libgnutls-openssl27 >= 3.2.15-11.1
  • libgnutls28 >= 3.2.15-11.1
  • libgnutls28-32bit >= 3.2.15-11.1
Patchnames:
SUSE Linux Enterprise Server 12 SP2 GA gnutls
SUSE Linux Enterprise Server 12 SP3
  • gnutls >= 3.3.27-1.10
  • libgnutls-openssl27 >= 3.3.27-1.10
  • libgnutls28 >= 3.3.27-1.10
  • libgnutls28-32bit >= 3.3.27-1.10
Patchnames:
SUSE Linux Enterprise Server 12 SP3 GA gnutls
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
  • gnutls >= 3.2.15-11.1
  • libgnutls-openssl27 >= 3.2.15-11.1
  • libgnutls28 >= 3.2.15-11.1
Patchnames:
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 GA gnutls
SUSE Linux Enterprise Software Development Kit 12
  • libgnutls-devel >= 3.2.15-1.8
  • libgnutls-openssl-devel >= 3.2.15-1.8
  • libgnutlsxx-devel >= 3.2.15-1.8
  • libgnutlsxx28 >= 3.2.15-1.8
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 GA libgnutls-devel
SUSE Linux Enterprise Software Development Kit 12 SP1
  • libgnutls-devel >= 3.2.15-11.1
  • libgnutls-openssl-devel >= 3.2.15-11.1
  • libgnutlsxx-devel >= 3.2.15-11.1
  • libgnutlsxx28 >= 3.2.15-11.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP1 GA libgnutls-devel
SUSE Linux Enterprise Software Development Kit 12 SP2
  • libgnutls-devel >= 3.2.15-11.1
  • libgnutls-openssl-devel >= 3.2.15-11.1
  • libgnutlsxx-devel >= 3.2.15-11.1
  • libgnutlsxx28 >= 3.2.15-11.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP2 GA libgnutls-devel
SUSE Linux Enterprise Software Development Kit 12 SP3
  • libgnutls-devel >= 3.3.27-1.10
  • libgnutls-openssl-devel >= 3.3.27-1.10
  • libgnutlsxx-devel >= 3.3.27-1.10
  • libgnutlsxx28 >= 3.3.27-1.10
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP3 GA libgnutls-devel
openSUSE Leap 15.0
  • gnutls >= 3.6.2-lp150.3.2
  • libgnutls-dane0 >= 3.6.2-lp150.3.2
  • libgnutls30 >= 3.6.2-lp150.3.2
Patchnames:
openSUSE Leap 15.0 GA gnutls
openSUSE Leap 42.1
  • gnutls >= 3.2.15-6.2
  • libgnutls-devel >= 3.2.15-6.2
  • libgnutls-openssl27 >= 3.2.15-6.2
  • libgnutls28 >= 3.2.15-6.2
  • libgnutls28-32bit >= 3.2.15-6.2
Patchnames:
openSUSE Leap 42.1 GA gnutls
openSUSE Leap 42.2
  • gnutls >= 3.2.15-7.5
  • libgnutls-devel >= 3.2.15-7.5
  • libgnutls-openssl27 >= 3.2.15-7.5
  • libgnutls28 >= 3.2.15-7.5
  • libgnutls28-32bit >= 3.2.15-7.5
Patchnames:
openSUSE Leap 42.2 GA gnutls
openSUSE Leap 42.3
  • gnutls >= 3.3.27-1.5
  • libgnutls-devel >= 3.3.27-1.5
  • libgnutls-openssl27 >= 3.3.27-1.5
  • libgnutls28 >= 3.3.27-1.5
  • libgnutls28-32bit >= 3.3.27-1.5
Patchnames:
openSUSE Leap 42.3 GA gnutls
openSUSE Tumbleweed
  • gnutls >= 3.4.15-1.1
  • gnutls-guile >= 3.4.15-1.1
  • libgnutls-dane-devel >= 3.4.15-1.1
  • libgnutls-dane0 >= 3.4.15-1.1
  • libgnutls-devel >= 3.4.15-1.1
  • libgnutls-devel-32bit >= 3.4.15-1.1
  • libgnutls-openssl-devel >= 3.4.15-1.1
  • libgnutls-openssl27 >= 3.4.15-1.1
  • libgnutls30 >= 3.4.15-1.1
  • libgnutls30-32bit >= 3.4.15-1.1
  • libgnutlsxx-devel >= 3.4.15-1.1
  • libgnutlsxx28 >= 3.4.15-1.1
Patchnames:
openSUSE Tumbleweed GA gnutls