Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

SUSE: 2014:0323-1 Critical: GnuTLS Certificate Verification Issue

suse
Calendar Grey March 4, 2014
Scroller Suse
SUSE has released a vital update for gnutls to address a vulnerability and enhance the process of certificate validation. Prompt attention is recommended.
An update that solves one vulnerability and has two fixes An update that solves one vulnerability and has two fixes An update that solves one vulnerability and has two fixes is now...

Summary

The GnuTLS library received a critical security fix and other updates: * CVE-2014-0092: The X.509 certificate verification had incorrect error handling, which could lead to broken certificates marked as being valid. * CVE-2009-5138: A verification problem in handling V1 certificates could also lead to V1 certificates incorrectly being handled. Additionally, a memory leak in PSK authentication was fixed. bnc#835760 Security Issues: * CVE-2014-0092 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11 SP2 LTSS: zypper in -t patch slessp2-gnutls-8950 To bring your system up-to-date, use "zypper patch".

References

#835760 #865804 #865993

Cross- CVE-2014-0092

Affected Products:

SUSE Linux Enterprise Server 11 SP2 LTSS

https://www.suse.com/security/cve/CVE-2014-0092.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0323-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.