Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

SUSE: 2014:0320-1 Critical GnuTLS Security Update Addressing DoS Risks

suse
Calendar Grey March 4, 2014
Scroller Suse
Essential patch for openssl addresses several vulnerabilities in Fedora platforms with key improvements and insights shared.
An update that solves 9 vulnerabilities and has one errata An update that solves 9 vulnerabilities and has one errata An update that solves 9 vulnerabilities and has one errata is ...

Summary

The GnuTLS library received a critical security fix and other updates: * CVE-2014-0092: The X.509 certificate verification had incorrect error handling, which could lead to broken certificates marked as being valid. * CVE-2009-5138: A verification problem in handling V1 certificates could also lead to V1 certificates incorrectly being handled. * CVE-2013-2116: The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS allowed remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length. * CVE-2013-1619: The TLS implementation in GnuTLS did not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to

References

#536809 #554084 #659128 #739898 #753301 #754223

#802651 #821818 #865804 #865993

Cross- CVE-2009-5138 CVE-2011-4108 CVE-2012-0390

CVE-2012-1569 CVE-2012-1573 CVE-2013-0169

CVE-2013-1619 CVE-2013-2116 CVE-2014-0092

Affected Products:

SUSE Linux Enterprise Server 10 SP3 LTSS

https://www.suse.com/security/cve/CVE-2009-5138.html

https://www.suse.com/security/cve/CVE-2011-4108.html

https://www.suse.com/security/cve/CVE-2012-0390.html

https://www.suse.com/security/cve/CVE-2012-1569.html

https://www.suse.com/security/cve/CVE-2012-1573.html

https://www.suse.com/security/cve/CVE-2013-0169.html

https://www.suse.com/security/cve/CVE-2013-1619.html

https://www.suse.com/security/cve/CVE-2013-2116.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0320-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.