|
|
Log in / Subscribe / Register

Scientific Linux alert SLSA-2014:0247-1 (gnutls)

From:  Pat Riehecky <riehecky@fnal.gov>
To:  <scientific-linux-errata@listserv.fnal.gov>
Subject:  Security ERRATA Important: gnutls on SL5.x i386/x86_64
Date:  Mon, 3 Mar 2014 19:32:55 +0000
Message-ID:  <20140303193255.28734.4636@slpackages.fnal.gov>

Synopsis: Important: gnutls security update Advisory ID: SLSA-2014:0247-1 Issue Date: 2014-03-03 CVE Numbers: CVE-2014-0092 CVE-2009-5138 -- It was discovered that GnuTLS did not correctly handle certain errors that could occur during the verification of an X.509 certificate, causing it to incorrectly report a successful verification. An attacker could use this flaw to create a specially crafted certificate that could be accepted by GnuTLS as valid for a site chosen by the attacker. (CVE-2014-0092) A flaw was found in the way GnuTLS handled version 1 X.509 certificates. An attacker able to obtain a version 1 certificate from a trusted certificate authority could use this flaw to issue certificates for other sites that would be accepted by GnuTLS as valid. (CVE-2009-5138) For the update to take effect, all applications linked to the GnuTLS library must be restarted. -- SL5 x86_64 gnutls-1.4.1-14.el5_10.i386.rpm gnutls-1.4.1-14.el5_10.x86_64.rpm gnutls-debuginfo-1.4.1-14.el5_10.i386.rpm gnutls-debuginfo-1.4.1-14.el5_10.x86_64.rpm gnutls-utils-1.4.1-14.el5_10.x86_64.rpm gnutls-devel-1.4.1-14.el5_10.i386.rpm gnutls-devel-1.4.1-14.el5_10.x86_64.rpm i386 gnutls-1.4.1-14.el5_10.i386.rpm gnutls-debuginfo-1.4.1-14.el5_10.i386.rpm gnutls-utils-1.4.1-14.el5_10.i386.rpm gnutls-devel-1.4.1-14.el5_10.i386.rpm - Scientific Linux Development Team


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds