Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

openSUSE 11.4: openSUSE-SU-2014:0767-1 Important: gnutls Memory Issue

opensuse
Calendar Grey June 6, 2014
Dist Opensuse Esm H88
Essential openSUSE patch tackles memory leakage and availability issues in libgcrypt, enhancing overall system security.
An update that fixes one vulnerability is now available

Description

gnutls was patched to fix security vulnerability that could be used to

disrupt service or potentially allow remote code execution.

- Memory corruption during connect (CVE-2014-3466)

- NULL pointer dereference in gnutls_x509_dn_oid_name (CVE-2014-3465)

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 11.4:

zypper in -t patch 2014-59

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 11.4 (i586 x86_64):

gnutls-2.8.6-5.29.1

gnutls-debuginfo-2.8.6-5.29.1

gnutls-debugsource-2.8.6-5.29.1

libgnutls-devel-2.8.6-5.29.1

libgnutls-extra-devel-2.8.6-5.29.1

libgnutls-extra26-2.8.6-5.29.1

libgnutls-extra26-debuginfo-2.8.6-5.29.1

libgnutls26-2.8.6-5.29.1

libgnutls26-debuginfo-2.8.6-5.29.1

- openSUSE 11.4 (x86_64):

libgnutls26-32bit-2.8.6-5.29.1

libgnutls26-debuginfo-32bit-2.8.6-5.29.1

- openSUSE 11.4 (ia64):

libgnutls26-debuginfo-x86-2.8.6-5.29.1

libgnutls26-x86-2.8.6-5.29.1

References

https://www.suse.com/security/cve/CVE-2014-3466.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2014:0767-1
Rating: important
Affected Products: openSUSE 11.4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here