CVE-2015-0294

EUVD-2015-0307
GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
Affected Products (NVD)
VendorProductVersion
gnugnutls
𝑥
< 3.3.13
debiandebian_linux
7.0
redhatenterprise_linux
5.0
redhatenterprise_linux
7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gnutls28
bookworm
3.7.9-2+deb12u3
fixed
bullseye
3.7.1-5+deb11u5
fixed
bullseye (security)
3.7.1-5+deb11u6
fixed
sid
3.8.6-2
fixed
trixie
3.8.6-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gnutls26
artful
dne
bionic
dne
cosmic
dne
disco
dne
lucid
Fixed 2.8.5-2ubuntu0.7
released
precise
Fixed 2.12.14-5ubuntu3.9
released
trusty
Fixed 2.12.23-12ubuntu2.2
released
utopic
ignored
vivid
dne
wily
dne
xenial
dne
yakkety
dne
zesty
dne
gnutls28
artful
Fixed 3.3.8-3ubuntu3
released
bionic
Fixed 3.3.8-3ubuntu3
released
cosmic
Fixed 3.3.8-3ubuntu3
released
disco
Fixed 3.3.8-3ubuntu3
released
lucid
dne
precise
ignored
trusty
dne
utopic
Fixed 3.2.16-1ubuntu2.2
released
vivid
Fixed 3.3.8-3ubuntu3
released
wily
Fixed 3.3.8-3ubuntu3
released
xenial
Fixed 3.3.8-3ubuntu3
released
yakkety
Fixed 3.3.8-3ubuntu3
released
zesty
Fixed 3.3.8-3ubuntu3
released