SCIENTIFIC-LINUX-ERRATA Archives

March 2014

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Mon, 3 Mar 2014 19:33:03 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (36 lines)
Synopsis:          Important: gnutls security update
Advisory ID:       SLSA-2014:0246-1
Issue Date:        2014-03-03
CVE Numbers:       CVE-2014-0092
--

It was discovered that GnuTLS did not correctly handle certain errors that
could occur during the verification of an X.509 certificate, causing it to
incorrectly report a successful verification. An attacker could use this
flaw to create a specially crafted certificate that could be accepted by
GnuTLS as valid for a site chosen by the attacker. (CVE-2014-0092)

For the update to take effect, all applications linked to the GnuTLS
library must be restarted.
--

SL6
  x86_64
    gnutls-2.8.5-13.el6_5.i686.rpm
    gnutls-2.8.5-13.el6_5.x86_64.rpm
    gnutls-debuginfo-2.8.5-13.el6_5.i686.rpm
    gnutls-debuginfo-2.8.5-13.el6_5.x86_64.rpm
    gnutls-utils-2.8.5-13.el6_5.x86_64.rpm
    gnutls-devel-2.8.5-13.el6_5.i686.rpm
    gnutls-devel-2.8.5-13.el6_5.x86_64.rpm
    gnutls-guile-2.8.5-13.el6_5.i686.rpm
    gnutls-guile-2.8.5-13.el6_5.x86_64.rpm
  i386
    gnutls-2.8.5-13.el6_5.i686.rpm
    gnutls-debuginfo-2.8.5-13.el6_5.i686.rpm
    gnutls-utils-2.8.5-13.el6_5.i686.rpm
    gnutls-devel-2.8.5-13.el6_5.i686.rpm
    gnutls-guile-2.8.5-13.el6_5.i686.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2