Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

Ubuntu: 1419-2 Significant: OpenSSL Denial Of Service Risk

ubuntu
Calendar Grey April 5, 2012
Scroller Ubuntu
Enhance your Ubuntu installation by resolving the GnuTLS vulnerabilities highlighted on April 05, 2012, to avoid any potential system failures.
The GnuTLS library could be made to crash under certain conditions.

Summary

The GnuTLS library could be made to crash under certain conditions.

Software Description:

- gnutls26: the GNU TLS library - commandline utilities

- gnutls13: the GNU TLS library - commandline utilities

Details:

Alban Crequy discovered that the GnuTLS library incorrectly checked array

bounds when copying TLS session data. A remote attacker could crash a client

application, leading to a denial of service, as the client application prepared

for TLS session resumption. (CVE-2011-4128)

Matthew Hall discovered that the GnuTLS library incorrectly handled TLS

records. A remote attacker could crash client and server applications, leading

to a denial of service, by sending a crafted TLS record. (CVE-2012-1573)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  libgnutls26                     2.10.5-1ubuntu3.1

Ubuntu 11.04:
  libgnutls26                     2.8.6-1ubuntu2.1

Ubuntu 10.10:
  libgnutls26                     2.8.6-1ubuntu0.1

Ubuntu 10.04 LTS:
  libgnutls26                     2.8.5-2ubuntu0.1

Ubuntu 8.04 LTS:
  libgnutls13                     2.0.4-1ubuntu2.7

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1418-1

CVE-2011-4128, CVE-2012-1573

Severity
critical
Lowest
Low
Medium
High
Critical

April 05, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.