LWN.net Logo

gnutls: denial of service

Package(s):gnutls26 CVE #(s):CVE-2013-2116
Created:May 30, 2013 Updated:July 5, 2013
Description: From the Debian advisory:

It was discovered that a malicious client could crash a GNUTLS server and vice versa, by sending TLS records encrypted with a block cipher which contain invalid padding.

Alerts:
Debian DSA-2697-1 2013-05-29
Ubuntu USN-1843-1 2013-05-29
Red Hat RHSA-2013:0883-01 2013-05-30
CentOS CESA-2013:0883 2013-05-30
Mandriva MDVSA-2013:171 2013-05-30
Oracle ELSA-2013-0883 2013-05-30
Oracle ELSA-2013-0883 2013-05-30
Scientific Linux SL-gnut-20130530 2013-05-30
Fedora FEDORA-2013-9783 2013-06-11
Fedora FEDORA-2013-9774 2013-06-11
Fedora FEDORA-2013-9792 2013-06-11
Fedora FEDORA-2013-9799 2013-06-11
SUSE SUSE-SU-2013:1060-1 2013-06-20
SUSE SUSE-SU-2013:1060-2 2013-07-04

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds