from http://www.gnutls.org/security.html#GNUTLS-SA-2014-5 Sean Burford reported that the encoding of elliptic curves parameters GnuTLS 3 is vulnerable to a denial of service (heap corruption). It affects clients and servers which print information about the peer's certificate, e.g., the key ID, and can be exploited via a specially crafted X.509 certificate.
gnutls-3.3.10-1.fc21 has been submitted as an update for Fedora 21. https://admin.fedoraproject.org/updates/gnutls-3.3.10-1.fc21
*** This bug has been marked as a duplicate of bug 1162086 ***