SCIENTIFIC-LINUX-ERRATA Archives

March 2012

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Patrick Riehecky <[log in to unmask]>
Reply To:
Date:
Wed, 28 Mar 2012 11:17:34 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (45 lines)
Synopsis:    Important: gnutls security update
Issue Date:  2012-03-27
CVE Numbers: CVE-2011-4128
             CVE-2012-1573


The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS).

A flaw was found in the way GnuTLS decrypted malformed TLS records. This
could cause a TLS/SSL client or server to crash when processing a
specially-crafted TLS record from a remote TLS/SSL connection peer.
(CVE-2012-1573)

A boundary error was found in the gnutls_session_get_data() function. A
malicious TLS/SSL server could use this flaw to crash a TLS/SSL client or,
possibly, execute arbitrary code as the client, if the client passed a
fixed-sized buffer to gnutls_session_get_data() before checking the real
size of the session data provided by the server. (CVE-2011-4128)

Users of GnuTLS are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. For the update to take
effect, all applications linked to the GnuTLS library must be restarted, or
the system rebooted.

SL6:
  i386
     gnutls-2.8.5-4.el6_2.2.i686.rpm
     gnutls-debuginfo-2.8.5-4.el6_2.2.i686.rpm
     gnutls-devel-2.8.5-4.el6_2.2.i686.rpm
     gnutls-guile-2.8.5-4.el6_2.2.i686.rpm
     gnutls-utils-2.8.5-4.el6_2.2.i686.rpm
  x86_64
     gnutls-2.8.5-4.el6_2.2.i686.rpm
     gnutls-2.8.5-4.el6_2.2.x86_64.rpm
     gnutls-debuginfo-2.8.5-4.el6_2.2.i686.rpm
     gnutls-debuginfo-2.8.5-4.el6_2.2.x86_64.rpm
     gnutls-devel-2.8.5-4.el6_2.2.i686.rpm
     gnutls-devel-2.8.5-4.el6_2.2.x86_64.rpm
     gnutls-guile-2.8.5-4.el6_2.2.i686.rpm
     gnutls-guile-2.8.5-4.el6_2.2.x86_64.rpm
     gnutls-utils-2.8.5-4.el6_2.2.x86_64.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2