MGASA-2020-0168 - Updated gnutls packages fix security vulnerability

Publication date: 15 Apr 2020
URL: https://advisories.mageia.org/MGASA-2020-0168.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2020-11501

Updated gnutls packages fix security vulnerability:

A flaw was reported in the DTLS protocol implementation in GnuTLS. The
DTLS client would not contribute any randomness to the DTLS negotiation,
breaking the security guarantees of the DTLS protocol (CVE-2020-11501).

References:
- https://bugs.mageia.org/show_bug.cgi?id=26444
- https://www.debian.org/security/2020/dsa-4652
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11501

SRPMS:
- 7/core/gnutls-3.6.7-1.1.mga7

Mageia 2020-0168: gnutls security update

Updated gnutls packages fix security vulnerability: A flaw was reported in the DTLS protocol implementation in GnuTLS

Summary

Updated gnutls packages fix security vulnerability:
A flaw was reported in the DTLS protocol implementation in GnuTLS. The DTLS client would not contribute any randomness to the DTLS negotiation, breaking the security guarantees of the DTLS protocol (CVE-2020-11501).

References

- https://bugs.mageia.org/show_bug.cgi?id=26444

- https://www.debian.org/security/2020/dsa-4652

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11501

Resolution

MGASA-2020-0168 - Updated gnutls packages fix security vulnerability

SRPMS

- 7/core/gnutls-3.6.7-1.1.mga7

Severity
Publication date: 15 Apr 2020
URL: https://advisories.mageia.org/MGASA-2020-0168.html
Type: security
CVE: CVE-2020-11501

Related News