Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 550
Alerts This Week
Warning Icon 1 550

SUSE: 2014:0758-2 Important: GnuTLS Memory Issues and DoS

suse
Calendar Grey June 13, 2014
Scroller Suse
SUSE has unveiled a Security Patch for OpenSSL that tackles severe vulnerabilities such as buffer overflows and Denial of Service (DoS) risks in anticipation of forthcoming updates.
An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is ...

Summary

GnuTLS has been patched to ensure proper parsing of session ids during the TLS/SSL handshake. Additionally three issues inherited from libtasn1 have been fixed. Further information is available at http://www.gnutls.org/security.html#GNUTLS-SA-2014-3 These security issues have been fixed: * Possible memory corruption during connect (CVE-2014-3466) * Multiple boundary check issues could allow DoS (CVE-2014-3467) * asn1_get_bit_der() can return negative bit length (CVE-2014-3468) * Possible DoS by NULL pointer dereference (CVE-2014-3469) Security Issue references: * CVE-2014-3466 Patch Instructions:

References

#880730 #880910

Cross- CVE-2014-3466

Affected Products:

SUSE Manager 1.7 for SLE 11 SP2

https://www.suse.com/security/cve/CVE-2014-3466.html

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0758-2
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.