Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE 11 SP3: 2014:0319-1 Critical: GnuTLS Certificate Issue

suse
Calendar Grey March 4, 2014
Scroller Suse
SUSE Security Patch addresses severe gnutls vulnerabilities, tackling memory leaks and issues with certificate verification for multiple distributions.
An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now avai...

Summary

The GnuTLS library received a critical security fix and other updates: * CVE-2014-0092: The X.509 certificate verification had incorrect error handling, which could lead to broken certificates marked as being valid. * CVE-2009-5138: A verification problem in handling V1 certificates could also lead to V1 certificates incorrectly being handled. Additionally a memory leak in PSK authentication has been fixed (bnc#835760). Security Issue references: * CVE-2014-0092 * CVE-2009-5138 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product:

References

#835760 #865804 #865993

Cross- CVE-2009-5138 CVE-2014-0092

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP3

SUSE Linux Enterprise Server 11 SP3 for VMware

SUSE Linux Enterprise Server 11 SP3

SUSE Linux Enterprise High Availability Extension 11 SP3

SUSE Linux Enterprise Desktop 11 SP3

https://www.suse.com/security/cve/CVE-2009-5138.html

https://www.suse.com/security/cve/CVE-2014-0092.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0319-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.