Oval Definition:oval:com.redhat.rhsa:def:20060680
Revision Date:2006-09-14Version:637
Title:RHSA-2006:0680: gnutls security update (Important)
Description:The GnuTLS Library provides support for cryptographic algorithms and protocols such as TLS. GnuTLS includes libtasn1, a library developed for ASN.1 structures management that includes DER encoding and decoding.

Daniel Bleichenbacher recently described an attack on PKCS #1 v1.5 signatures. Where an RSA key with exponent 3 is used it may be possible for an attacker to forge a PKCS #1 v1.5 signature that would be incorrectly verified by implementations that do not check for excess data in the RSA exponentiation result of the signature.

  • The core GnuTLS team discovered that GnuTLS is vulnerable to a variant of the Bleichenbacker attack. This issue affects applications that use GnuTLS to verify X.509 certificates as well as other uses of PKCS #1 v1.5. (CVE-2006-4790)

    In Red Hat Enterprise Linux 4, the GnuTLS library is only used by the Evolution client when connecting to an Exchange server or when publishing calendar information to a WebDAV server.

    Users are advised to upgrade to these updated packages, which contain a backported patch from the GnuTLS maintainers to correct this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2006-4790
    RHSA-2006:0680
    RHSA-2006:0680-01
    RHSA-2006:0680-01
    Platform(s):Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • gnutls is earlier than 0:1.0.20-3.2.3
  • AND gnutls is signed with Red Hat redhatrelease2 key
  • gnutls-devel is earlier than 0:1.0.20-3.2.3
  • AND gnutls-devel is signed with Red Hat redhatrelease2 key
  • BACK