Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

SUSE: 2019:1121-1 Important: Gnutls Double Free and TLS Issues

suse
Calendar Grey April 30, 2019
Dist Suse Esm H88
Critical GnuTLS security enhancement for SUSE tackling three vulnerabilities along with detailed guidance for applying the patches.
An update that fixes three vulnerabilities is now available

Summary

This update for gnutls fixes to version 3.6.7 the following issues: Security issued fixed: - CVE-2019-3836: Fixed an invalid pointer access via malformed TLS1.3 async messages (bsc#1130682). - CVE-2019-3829: Fixed a double free vulnerability in the certificate verification API (bsc#1130681). - CVE-2018-16868: Fixed Bleichenbacher-like side channel leakage in PKCS#1 v1.5 verification and padding oracle verification (bsc#1118087) Non-security issue fixed: - Update gnutls to support TLS 1.3 (fate#327114) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15:

References

#1118087 #1130681 #1130682

Cross- CVE-2018-16868 CVE-2019-3829 CVE-2019-3836

Affected Products:

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15

SUSE Linux Enterprise Module for Desktop Applications 15

SUSE Linux Enterprise Module for Basesystem 15

https://www.suse.com/security/cve/CVE-2018-16868.html

https://www.suse.com/security/cve/CVE-2019-3829.html

https://www.suse.com/security/cve/CVE-2019-3836.html

https://bugzilla.suse.com/1118087

https://bugzilla.suse.com/1130681

https://bugzilla.suse.com/1130682

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:1121-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here