RULE(RULE ID:709370)

Rule General Information
Release Date: 2015-03-16
Rule Name: Gnutls X.509 Intermediate Certificate Policy Bypass Vulnerability (CVE-2014-1959)
Severity:
CVE ID:
Rule Protection Details
Description: lib/x509/verify.c in GnuTLS before 3.1.21 and 3.2.x before 3.2.11 treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to bypass intended restrictions by leveraging a X.509 V1 certificate from a trusted CA to issue new certificates.
Impact: An attacker can take advantage of the vulnerability to bypass the security policy implemented by the software administrator, and perform unauthorized actions to the target system.
Affected OS: Windows, Solaris, Other Unix, FreeBSD, Linux
Reference: SecurityFocusBID:65559
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://www.gnutls.org/security.html#GNUTLS-SA-2014-1