Oval Definition:oval:com.redhat.rhsa:def:20080492
Revision Date:2008-05-20Version:639
Title:RHSA-2008:0492: gnutls security update (Important)
Description:The GnuTLS Library provides support for cryptographic algorithms and protocols such as TLS. GnuTLS includes libtasn1, a library developed for ASN.1 structures management that includes DER encoding and decoding.

  • Flaws were found in the way GnuTLS handles malicious client connections. A malicious remote client could send a specially crafted request to a service using GnuTLS that could cause the service to crash. (CVE-2008-1948, CVE-2008-1949, CVE-2008-1950)

    We believe it is possible to leverage the flaw CVE-2008-1948 to execute arbitrary code but have been unable to prove this at the time of releasing this advisory. Red Hat Enterprise Linux 4 does not ship with any applications directly affected by this flaw. Third-party software which runs on Red Hat Enterprise Linux 4 could, however, be affected by this vulnerability. Consequently, we have assigned it important severity.

    Users of GnuTLS are advised to upgrade to these updated packages, which contain a backported patch that corrects these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2008-1948
    CVE-2008-1949
    CVE-2008-1950
    RHSA-2008:0492
    RHSA-2008:0492-01
    RHSA-2008:0492-01
    Platform(s):Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • gnutls is earlier than 0:1.0.20-4.el4_6
  • AND gnutls is signed with Red Hat redhatrelease2 key
  • gnutls-devel is earlier than 0:1.0.20-4.el4_6
  • AND gnutls-devel is signed with Red Hat redhatrelease2 key
  • BACK