Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

SUSE: 2014:0810-2 Critical: OpenSSL Vulnerability and Security Updates

suse
Calendar Grey June 16, 2014
Scroller Suse
SUSE releases GnuTLS patch mitigating various security flaws, including risks of potential buffer overflows and denial-of-service attacks.
An update that fixes 5 vulnerabilities is now available

Summary

GnuTLS has been patched to ensure proper parsing of session ids during the TLS/SSL handshake. Additionally three issues inherited from libtasn1 have been fixed. Further information is available at http://www.gnutls.org/security.html#GNUTLS-SA-2014-3 These security issues have been fixed: * Possible memory corruption during connect (CVE-2014-3466) * Multiple boundary check issues could allow DoS (CVE-2014-3467) * asn1_get_bit_der() can return negative bit length (CVE-2014-3468) * Possible DoS by NULL pointer dereference (CVE-2014-3469) * Possible timing side-channel attack (Lucky 13) (CVE-2013-1619) One additional bug has been fixed: * Allow unsafe renegotiation (bnc#554084) Security Issue references: * CVE-2014-3466

References

#554084 #670152 #802651 #880730 #880910

Cross- CVE-2013-1619 CVE-2014-3466 CVE-2014-3467

CVE-2014-3468 CVE-2014-3469

Affected Products:

SUSE CORE 9

https://www.suse.com/security/cve/CVE-2013-1619.html

https://www.suse.com/security/cve/CVE-2014-3466.html

https://www.suse.com/security/cve/CVE-2014-3467.html

https://www.suse.com/security/cve/CVE-2014-3468.html

https://www.suse.com/security/cve/CVE-2014-3469.html

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0800-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.