Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Critical Alert for Scientific Linux 5x: SLSA-2014:0594-1 GnuTLS Issue

Scientific Large Esm H446
Important: gnutls security update
Date: Tue, 3 Jun 2014 09:02:41 -0500
Reply-To: Bonnie King 
Sender: Security Errata for Scientific Linux
 
From: Bonnie King 
Subject: FASTBUGS for SL 5x i386, x86_64 now available
Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it.
In-Reply-To: <537B6682.4010808@fnal.gov>
MIME-Version: 1.0

The following FASTBUGS have been uploaded to

i386:
gfs2-utils-0.1.62-39.el5_10.3.i386.rpm
java-1.7.0-openjdk-1.7.0.55-2.4.7.2.el5_10.i386.rpm
java-1.7.0-openjdk-demo-1.7.0.55-2.4.7.2.el5_10.i386.rpm
java-1.7.0-openjdk-devel-1.7.0.55-2.4.7.2.el5_10.i386.rpm
java-1.7.0-openjdk-javadoc-1.7.0.55-2.4.7.2.el5_10.i386.rpm
java-1.7.0-openjdk-src-1.7.0.55-2.4.7.2.el5_10.i386.rpm
tzdata-2014d-1.el5.i386.rpm
tzdata-java-2014d-1.el5.i386.rpm

x86_64:
gfs2-utils-0.1.62-39.el5_10.3.x86_64.rpm
java-1.7.0-openjdk-1.7.0.55-2.4.7.2.el5_10.x86_64.rpm
java-1.7.0-openjdk-demo-1.7.0.55-2.4.7.2.el5_10.x86_64.rpm
java-1.7.0-openjdk-devel-1.7.0.55-2.4.7.2.el5_10.x86_64.rpm
java-1.7.0-openjdk-javadoc-1.7.0.55-2.4.7.2.el5_10.x86_64.rpm
java-1.7.0-openjdk-src-1.7.0.55-2.4.7.2.el5_10.x86_64.rpm
Date: Tue, 3 Jun 2014 09:02:56 -0500
Reply-To: Bonnie King 
Sender: Security Errata for Scientific Linux
 
From: Bonnie King 
Subject: FASTBUGS for SL 6x i386, x86_64 now available
Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it.
In-Reply-To: <537B666E.20201@fnal.gov>
MIME-Version: 1.0

The following FASTBUGS have been uploaded to

i386:
389-ds-base-1.2.11.15-33.el6_5.i686.rpm
389-ds-base-devel-1.2.11.15-33.el6_5.i686.rpm
389-ds-base-libs-1.2.11.15-33.el6_5.i686.rpm
audispd-plugins-2.2-4.el6_5.i686.rpm
audit-2.2-4.el6_5.i686.rpm
audit-libs-2.2-4.el6_5.i686.rpm
audit-libs-devel-2.2-4.el6_5.i686.rpm
audit-libs-python-2.2-4.el6_5.i686.rpm
audit-libs-static-2.2-4.el6_5.i686.rpm
finger-0.17-40.el6.i686.rpm
finger-server-0.17-40.el6.i686.rpm
gettext-0.17-18.el6.i686.rpm
gettext-devel-0.17-18.el6.i686.rpm
gettext-libs-0.17-18.el6.i686.rpm
gvfs-1.4.3-16.el6_5.i686.rpm
gvfs-afc-1.4.3-16.el6_5.i686.rpm
gvfs-archive-1.4.3-16.el6_5.i686.rpm
gvfs-devel-1.4.3-16.el6_5.i686.rpm
gvfs-fuse-1.4.3-16.el6_5.i686.rpm
gvfs-gphoto2-1.4.3-16.el6_5.i686.rpm
gvfs-obexftp-1.4.3-16.el6_5.i686.rpm
gvfs-smb-1.4.3-16.el6_5.i686.rpm
ibus-table-1.2.0.20100111-5.el6.noarch.rpm
ibus-table-additional-1.2.0.20100111-5.el6.noarch.rpm
ibus-table-devel-1.2.0.20100111-5.el6.noarch.rpm
iproute-2.6.32-32.el6_5.i686.rpm
iproute-devel-2.6.32-32.el6_5.i686.rpm
iproute-doc-2.6.32-32.el6_5.i686.rpm
openmotif-2.3.3-7.1.el6_5.i686.rpm
openmotif-devel-2.3.3-7.1.el6_5.i686.rpm
pango-1.28.1-10.el6.i686.rpm
pango-devel-1.28.1-10.el6.i686.rpm
perl-WWW-Curl-4.09-4.el6.i686.rpm
tzdata-2014d-1.el6.noarch.rpm
tzdata-java-2014d-1.el6.noarch.rpm

x86_64:
389-ds-base-1.2.11.15-33.el6_5.x86_64.rpm
389-ds-base-devel-1.2.11.15-33.el6_5.i686.rpm
389-ds-base-devel-1.2.11.15-33.el6_5.x86_64.rpm
389-ds-base-libs-1.2.11.15-33.el6_5.i686.rpm
389-ds-base-libs-1.2.11.15-33.el6_5.x86_64.rpm
audispd-plugins-2.2-4.el6_5.x86_64.rpm
audit-2.2-4.el6_5.x86_64.rpm
audit-libs-2.2-4.el6_5.i686.rpm
audit-libs-2.2-4.el6_5.x86_64.rpm
audit-libs-devel-2.2-4.el6_5.i686.rpm
audit-libs-devel-2.2-4.el6_5.x86_64.rpm
audit-libs-python-2.2-4.el6_5.x86_64.rpm
audit-libs-static-2.2-4.el6_5.x86_64.rpm
finger-0.17-40.el6.x86_64.rpm
finger-server-0.17-40.el6.x86_64.rpm
gettext-0.17-18.el6.i686.rpm
gettext-0.17-18.el6.x86_64.rpm
gettext-devel-0.17-18.el6.i686.rpm
gettext-devel-0.17-18.el6.x86_64.rpm
gettext-libs-0.17-18.el6.i686.rpm
gettext-libs-0.17-18.el6.x86_64.rpm
gvfs-1.4.3-16.el6_5.i686.rpm
gvfs-1.4.3-16.el6_5.x86_64.rpm
gvfs-afc-1.4.3-16.el6_5.x86_64.rpm
gvfs-archive-1.4.3-16.el6_5.x86_64.rpm
gvfs-devel-1.4.3-16.el6_5.i686.rpm
gvfs-devel-1.4.3-16.el6_5.x86_64.rpm
gvfs-fuse-1.4.3-16.el6_5.x86_64.rpm
gvfs-gphoto2-1.4.3-16.el6_5.x86_64.rpm
gvfs-obexftp-1.4.3-16.el6_5.x86_64.rpm
gvfs-smb-1.4.3-16.el6_5.x86_64.rpm
ibus-table-1.2.0.20100111-5.el6.noarch.rpm
ibus-table-additional-1.2.0.20100111-5.el6.noarch.rpm
ibus-table-devel-1.2.0.20100111-5.el6.noarch.rpm
iproute-2.6.32-32.el6_5.x86_64.rpm
iproute-devel-2.6.32-32.el6_5.i686.rpm
iproute-devel-2.6.32-32.el6_5.x86_64.rpm
iproute-doc-2.6.32-32.el6_5.x86_64.rpm
openmotif-2.3.3-7.1.el6_5.i686.rpm
openmotif-2.3.3-7.1.el6_5.x86_64.rpm
openmotif-devel-2.3.3-7.1.el6_5.i686.rpm
openmotif-devel-2.3.3-7.1.el6_5.x86_64.rpm
pango-1.28.1-10.el6.i686.rpm
pango-1.28.1-10.el6.x86_64.rpm
pango-devel-1.28.1-10.el6.i686.rpm
pango-devel-1.28.1-10.el6.x86_64.rpm
perl-WWW-Curl-4.09-4.el6.x86_64.rpm
tzdata-2014d-1.el6.noarch.rpm
tzdata-java-2014d-1.el6.noarch.rpm
Date: Tue, 3 Jun 2014 17:12:32 +0000
Reply-To: scientific-linux-users@
Sender: Security Errata for Scientific Linux
 
From: Pat Riehecky 
Subject: Security ERRATA Important: gnutls on SL5.x i386/x86_64
MIME-Version: 1.0

Synopsis: Important: gnutls security update
Advisory ID: SLSA-2014:0594-1
Issue Date: 2014-06-03
CVE Numbers: CVE-2014-3466
 CVE-2014-3467
 CVE-2014-3468
 CVE-2014-3469
--

A flaw was found in the way GnuTLS parsed session IDs from ServerHello
messages of the TLS/SSL handshake. A malicious server could use this flaw
to send an excessively long session ID value, which would trigger a buffer
overflow in a connecting TLS/SSL client application using GnuTLS, causing
the client application to crash or, possibly, execute arbitrary code.
(CVE-2014-3466)

It was discovered that the asn1_get_bit_der() function of the libtasn1
library incorrectly reported the length of ASN.1-encoded data. Specially
crafted ASN.1 input could cause an application using libtasn1 to perform
an out-of-bounds access operation, causing the application to crash or,
possibly, execute arbitrary code. (CVE-2014-3468)

Multiple incorrect buffer boundary check issues were discovered in
libtasn1. Specially crafted ASN.1 input could cause an application using
libtasn1 to crash. (CVE-2014-3467)

Multiple NULL pointer dereference flaws were found in libtasn1's
asn1_read_value() function. Specially crafted ASN.1 input could cause an
application using libtasn1 to crash, if the application used the
aforementioned function in a certain way. (CVE-2014-3469)

For the update to take effect, all applications linked to the GnuTLS or
libtasn1 library must be restarted.
--

SL5
 x86_64
 gnutls-1.4.1-16.el5_10.i386.rpm
 gnutls-1.4.1-16.el5_10.x86_64.rpm
 gnutls-debuginfo-1.4.1-16.el5_10.i386.rpm
 gnutls-debuginfo-1.4.1-16.el5_10.x86_64.rpm
 gnutls-utils-1.4.1-16.el5_10.x86_64.rpm
 gnutls-devel-1.4.1-16.el5_10.i386.rpm
 gnutls-devel-1.4.1-16.el5_10.x86_64.rpm
 i386
 gnutls-1.4.1-16.el5_10.i386.rpm
 gnutls-debuginfo-1.4.1-16.el5_10.i386.rpm
 gnutls-utils-1.4.1-16.el5_10.i386.rpm
 gnutls-devel-1.4.1-16.el5_10.i386.rpm

- Scientific Linux Development Team