Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 10: 2009-8622 Medium Severity: NUL Handling in GnuTLS

fedora
Calendar Grey September 25, 2009
Dist Fedora Esm H88
New release of gnutls enhances handling of NUL characters in certificate elements and refines hostname comparison mechanisms.
This update fixes handling of NUL characters in certificate Common Name or subjectAltName fields especially in regards to comparsion to hostnames.

Summary

GnuTLS is a project that aims to develop a library which provides a secure

layer, over a reliable transport layer. Currently the GnuTLS library implements

the proposed standards by the IETF's TLS working group.

Update Information:

This update fixes handling of NUL characters in certificate Common Name or subjectAltName fields especially in regards to comparsion to hostnames.

Change Log

* Wed Sep 23 2009 Tomas Mraz 2.4.2-5 - fix handling of hostname in openpgp certificates * Fri Aug 14 2009 Tomas Mraz 2.4.2-4 - fix CVE-2009-2730 - handling of NUL chars in certificate CNs and SANs * Tue Nov 11 2008 Tomas Mraz 2.4.2-3 - fix chain verification issue CVE-2008-4989 (#470079)

References


[ 1 ] Bug #516231 - CVE-2009-2730 gnutls: incorrect verification of SSL certificate with NUL in name (GNUTLS-SA-2009-4) https://bugzilla.redhat.com/show_bug.cgi?id=516231

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update gnutls' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
medium
Lowest
Low
Medium
High
Critical

Name: gnutls
Product: Fedora 10
Version: 2.4.2
Release: 5.fc10
Summary: A TLS protocol implementation

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here