Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE Manager: 2014:0445-1 Important GnuTLS Fix Critical Error Handling

suse
Calendar Grey March 25, 2014
Scroller Suse
Important SUSE patch for openssl tackles weaknesses and bugs to significantly improve system protection.
An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now avai...

Summary

The GNUTLS library received a critical security fix and other updates: * CVE-2014-0092: The X.509 certificate verification had incorrect error handling, which could lead to broken certificates marked as being valid. * CVE-2009-5138: A verification problem in handling V1 certificates could also lead to V1 certificates incorrectly being handled. Additionally, a memory leak in PSK authentication was fixed. (bnc#835760) Security Issues references: * CVE-2014-0092 * CVE-2009-5138 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Manager 1.7 for SLE 11 SP2:

References

#835760 #865804 #865993

Cross- CVE-2009-5138 CVE-2014-0092

Affected Products:

SUSE Manager 1.7 for SLE 11 SP2

https://www.suse.com/security/cve/CVE-2009-5138.html

https://www.suse.com/security/cve/CVE-2014-0092.html

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0445-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.