Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2014:0322-1 Critical: GnuTLS Certificate Issues and DoS Fixes

suse
Calendar Grey March 4, 2014
Scroller Suse
SUSE Security Bulletin: Resolution for severe GnuTLS vulnerabilities; high severity rating and numerous security flaws resolved.
An update that solves four vulnerabilities and has two An update that solves four vulnerabilities and has two An update that solves four vulnerabilities and has two fixes is now av...

Summary

The GnuTLS library received a critical security fix and other updates: * CVE-2014-0092: The X.509 certificate verification had incorrect error handling, which could lead to broken certificates marked as being valid. * CVE-2009-5138: A verification problem in handling V1 certificates could also lead to V1 certificates incorrectly being handled. * CVE-2013-2116: The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS allowed remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length. * CVE-2013-1619: Timing attacks against hashing of padding was fixed which might have allowed disclosure of keys. (Lucky13 attack). Also the following non-security bugs have been fixed: * gnutls doesn't like root CAs without Basic

References

#760265 #802651 #821818 #835760 #865804 #865993

Cross- CVE-2009-5138 CVE-2013-1619 CVE-2013-2116

CVE-2014-0092

Affected Products:

SUSE Linux Enterprise Server 11 SP1 LTSS

https://www.suse.com/security/cve/CVE-2009-5138.html

https://www.suse.com/security/cve/CVE-2013-1619.html

https://www.suse.com/security/cve/CVE-2013-2116.html

https://www.suse.com/security/cve/CVE-2014-0092.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0322-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.