Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

SUSE: 2014:0810-2 Critical: OpenSSL Vulnerability and Security Updates

suse
Calendar Grey June 16, 2014
Dist Suse Esm H88
SUSE releases GnuTLS patch mitigating various security flaws, including risks of potential buffer overflows and denial-of-service attacks.
An update that fixes 5 vulnerabilities is now available

Summary

GnuTLS has been patched to ensure proper parsing of session ids during the TLS/SSL handshake. Additionally three issues inherited from libtasn1 have been fixed. Further information is available at http://www.gnutls.org/security.html#GNUTLS-SA-2014-3 These security issues have been fixed: * Possible memory corruption during connect (CVE-2014-3466) * Multiple boundary check issues could allow DoS (CVE-2014-3467) * asn1_get_bit_der() can return negative bit length (CVE-2014-3468) * Possible DoS by NULL pointer dereference (CVE-2014-3469) * Possible timing side-channel attack (Lucky 13) (CVE-2013-1619) One additional bug has been fixed: * Allow unsafe renegotiation (bnc#554084) Security Issue references: * CVE-2014-3466

References

#554084 #670152 #802651 #880730 #880910

Cross- CVE-2013-1619 CVE-2014-3466 CVE-2014-3467

CVE-2014-3468 CVE-2014-3469

Affected Products:

SUSE CORE 9

https://www.suse.com/security/cve/CVE-2013-1619.html

https://www.suse.com/security/cve/CVE-2014-3466.html

https://www.suse.com/security/cve/CVE-2014-3467.html

https://www.suse.com/security/cve/CVE-2014-3468.html

https://www.suse.com/security/cve/CVE-2014-3469.html

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0800-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here