TROYANOSYVIRUS
Voltar para CVEs

CVE-2014-8155

N/A

Descricao

GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-middle attackers to spoof servers via a certificate issued by a CA certificate that is (1) not yet valid or (2) no longer valid.

Detalhes CVE

Pontuacao CVSS v3.1N/A
Publicado8/14/2015
Ultima modificacao4/12/2025
Fontenvd
Avistamentos honeypot0

Produtos afetados

gnu:gnutls

Fraquezas (CWE)

CWE-17

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.