Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 550
Alerts This Week
Warning Icon 1 550

SUSE: 2014:0788-1 Important: GnuTLS DoS Fix And Memory Issues

suse
Calendar Grey June 13, 2014
Scroller Suse
SUSE has released a critical update for GnuTLS, tackling multiple vulnerabilities including potential memory leaks and Denial of Service risks. Comprehensive patch notes available.
An update that fixes four vulnerabilities is now available

Summary

GnuTLS was patched to ensure proper parsing of session ids during the TLS/SSL handshake. Additionally three issues inherited from libtasn1 were fixed. * Possible memory corruption during connect. (CVE-2014-3466) * Multiple boundary check issues could allow DoS. (CVE-2014-3467) * asn1_get_bit_der() can return negative bit length. (CVE-2014-3468) * Possible DoS by NULL pointer dereference. (CVE-2014-3469) Further information is available at http://www.gnutls.org/security.html#GNUTLS-SA-2014-3 . Security Issues references: * CVE-2014-3466 * CVE-2014-3467 * CVE-2014-3468

References

#880730 #880910

Cross- CVE-2014-3466 CVE-2014-3467 CVE-2014-3468

CVE-2014-3469

Affected Products:

SUSE Linux Enterprise Server 11 SP2 LTSS

SUSE Linux Enterprise Server 11 SP1 LTSS

https://www.suse.com/security/cve/CVE-2014-3466.html

https://www.suse.com/security/cve/CVE-2014-3467.html

https://www.suse.com/security/cve/CVE-2014-3468.html

https://www.suse.com/security/cve/CVE-2014-3469.html

https://scc.suse.com:443/patches/

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0788-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.