Oval Definition:oval:com.redhat.rhsa:def:20060207
Revision Date:2006-02-10Version:643
Title:RHSA-2006:0207: gnutls security update (Important)
Description:The GNU TLS Library provides support for cryptographic algorithms and protocols such as TLS. GNU TLS includes Libtasn1, a library developed for ASN.1 structures management that includes DER encoding and decoding.

Several flaws were found in the way libtasn1 decodes DER. An attacker could create a carefully crafted invalid X.509 certificate in such a way that could trigger this flaw if parsed by an application that uses GNU TLS. This could lead to a denial of service (application crash). It is not certain if this issue could be escalated to allow arbitrary code execution. The Common Vulnerabilities and Exposures project assigned the name CVE-2006-0645 to this issue.

In Red Hat Enterprise Linux 4, the GNU TLS library is only used by the Evolution client when connecting to an Exchange server or when publishing calendar information to a WebDAV server.

Users are advised to upgrade to these updated packages, which contain a backported patch from the GNU TLS maintainers to correct this issue.
Family:unixClass:patch
Status:Reference(s):CVE-2006-0645
RHSA-2006:0207
RHSA-2006:0207-01
RHSA-2006:0207-01
Platform(s):Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • gnutls is earlier than 0:1.0.20-3.2.2
  • AND gnutls is signed with Red Hat redhatrelease2 key
  • gnutls-devel is earlier than 0:1.0.20-3.2.2
  • AND gnutls-devel is signed with Red Hat redhatrelease2 key
  • BACK