=========================================================================Ubuntu Security Notice USN-4491-1
September 09, 2020

gnutls28 vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS

Summary:

GnuTLS could be made to crash or run programs if it received specially
crafted network traffic.

Software Description:
- gnutls28: GNU TLS library

Details:

It was discovered that GnuTLS incorrectly handled certain alerts when being
used with TLS 1.3 servers. A remote attacker could use this issue to cause
GnuTLS to crash, resulting in a denial of service, or possibly execute
arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
  libgnutls30                     3.6.13-2ubuntu1.3

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4491-1
  CVE-2020-24659

Package Information:
  https://launchpad.net/ubuntu/+source/gnutls28/3.6.13-2ubuntu1.3

Ubuntu 4491-1: GnuTLS vulnerability

September 9, 2020
GnuTLS could be made to crash or run programs if it received specially crafted network traffic.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: libgnutls30 3.6.13-2ubuntu1.3 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4491-1

CVE-2020-24659

Severity
September 09, 2020

Package Information

https://launchpad.net/ubuntu/+source/gnutls28/3.6.13-2ubuntu1.3

Related News