LWN.net Logo

gnutls: denial of service

Package(s):gnutls26 CVE #(s):CVE-2012-1573
Created:March 26, 2012 Updated:March 28, 2012
Description: From the Debian advisory:

Matthew Hall discovered that GNUTLS does not properly handle truncated GenericBlockCipher structures nested inside TLS records, leading to crashes in applications using the GNUTLS library.

Alerts:
Debian DSA-2441-1 2012-03-25
Fedora FEDORA-2012-4578 2012-03-26
Mandriva MDVSA-2012:040 2012-03-27
Red Hat RHSA-2012:0428-01 2012-03-27
Red Hat RHSA-2012:0429-01 2012-03-27
CentOS CESA-2012:0428 2012-03-28
CentOS CESA-2012:0429 2012-03-28
Scientific Linux SL-gnut-20120328 2012-03-28
Scientific Linux SL-gnut-20120328 2012-03-28
Oracle ELSA-2012-0428 2012-03-28
Oracle ELSA-2012-0429 2012-03-28
Ubuntu USN-1418-1 2012-04-05
Fedora FEDORA-2012-4569 2012-04-11
openSUSE openSUSE-SU-2012:0620-1 2012-05-15
Gentoo 201206-18 2012-06-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds