Scientific Linux alert SLSA-2014:0246-1 (gnutls)
| From: | Pat Riehecky <riehecky@fnal.gov> | |
| To: | <scientific-linux-errata@listserv.fnal.gov> | |
| Subject: | Security ERRATA Important: gnutls on SL6.x i386/x86_64 | |
| Date: | Mon, 3 Mar 2014 19:33:03 +0000 | |
| Message-ID: | <20140303193303.28734.9110@slpackages.fnal.gov> |
Synopsis: Important: gnutls security update Advisory ID: SLSA-2014:0246-1 Issue Date: 2014-03-03 CVE Numbers: CVE-2014-0092 -- It was discovered that GnuTLS did not correctly handle certain errors that could occur during the verification of an X.509 certificate, causing it to incorrectly report a successful verification. An attacker could use this flaw to create a specially crafted certificate that could be accepted by GnuTLS as valid for a site chosen by the attacker. (CVE-2014-0092) For the update to take effect, all applications linked to the GnuTLS library must be restarted. -- SL6 x86_64 gnutls-2.8.5-13.el6_5.i686.rpm gnutls-2.8.5-13.el6_5.x86_64.rpm gnutls-debuginfo-2.8.5-13.el6_5.i686.rpm gnutls-debuginfo-2.8.5-13.el6_5.x86_64.rpm gnutls-utils-2.8.5-13.el6_5.x86_64.rpm gnutls-devel-2.8.5-13.el6_5.i686.rpm gnutls-devel-2.8.5-13.el6_5.x86_64.rpm gnutls-guile-2.8.5-13.el6_5.i686.rpm gnutls-guile-2.8.5-13.el6_5.x86_64.rpm i386 gnutls-2.8.5-13.el6_5.i686.rpm gnutls-debuginfo-2.8.5-13.el6_5.i686.rpm gnutls-utils-2.8.5-13.el6_5.i686.rpm gnutls-devel-2.8.5-13.el6_5.i686.rpm gnutls-guile-2.8.5-13.el6_5.i686.rpm - Scientific Linux Development Team
