Synopsis:          Moderate: gnutls security update
Advisory ID:       SLSA-2014:1846-1
Issue Date:        2014-11-12
CVE Numbers:       CVE-2014-8564
--

An out-of-bounds memory write flaw was found in the way GnuTLS parsed
certain ECC (Elliptic Curve Cryptography) certificates or certificate
signing requests (CSR). A malicious user could create a specially crafted
ECC certificate or a certificate signing request that, when processed by
an application compiled against GnuTLS (for example, certtool), could
cause that application to crash or execute arbitrary code with the
permissions of the user running the application. (CVE-2014-8564)

For the update to take effect, all applications linked to the GnuTLS or
libtasn1 library must be restarted.
--

SL7
  x86_64
    gnutls-3.1.18-10.el7_0.i686.rpm
    gnutls-3.1.18-10.el7_0.x86_64.rpm
    gnutls-dane-3.1.18-10.el7_0.i686.rpm
    gnutls-dane-3.1.18-10.el7_0.x86_64.rpm
    gnutls-debuginfo-3.1.18-10.el7_0.i686.rpm
    gnutls-debuginfo-3.1.18-10.el7_0.x86_64.rpm
    gnutls-utils-3.1.18-10.el7_0.x86_64.rpm
    gnutls-c++-3.1.18-10.el7_0.i686.rpm
    gnutls-c++-3.1.18-10.el7_0.x86_64.rpm
    gnutls-devel-3.1.18-10.el7_0.i686.rpm
    gnutls-devel-3.1.18-10.el7_0.x86_64.rpm

- Scientific Linux Development Team