Oval Definition:oval:com.redhat.rhsa:def:20151457
Revision Date:2015-07-22Version:646
Title:RHSA-2015:1457: gnutls security and bug fix update (Moderate)
Description:The GnuTLS library provides support for cryptographic algorithms and for protocols such as Transport Layer Security (TLS).

  • It was found that GnuTLS did not check activation and expiration dates of CA certificates. This could cause an application using GnuTLS to incorrectly accept a certificate as valid when its issuing CA is already expired. (CVE-2014-8155)

  • It was found that GnuTLS did not verify whether a hashing algorithm listed in a signature matched the hashing algorithm listed in the certificate. An attacker could create a certificate that used a different hashing algorithm than it claimed, possibly causing GnuTLS to use an insecure, disallowed hashing algorithm during certificate verification. (CVE-2015-0282)

  • It was discovered that GnuTLS did not check if all sections of X.509 certificates indicate the same signature algorithm. This flaw, in combination with a different flaw, could possibly lead to a bypass of the certificate signature check. (CVE-2015-0294)

    The CVE-2014-8155 issue was discovered by Marcel Kolaja of Red Hat. The CVE-2015-0282 and CVE-2015-0294 issues were discovered by Nikos Mavrogiannopoulos of the Red Hat Security Technologies Team.

    This update also fixes the following bug:

  • Previously, under certain circumstances, the certtool utility could generate X.509 certificates which contained a negative modulus. Consequently, such certificates could have interoperation problems with the software using them. The bug has been fixed, and certtool no longer generates X.509 certificates containing a negative modulus. (BZ#1036385)

    Users of gnutls are advised to upgrade to these updated packages, which contain backported patches to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2014-8155
    CVE-2015-0282
    CVE-2015-0294
    RHSA-2015:1457
    RHSA-2015:1457-01
    RHSA-2015:1457-03
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • gnutls is earlier than 0:2.8.5-18.el6
  • AND gnutls is signed with Red Hat redhatrelease2 key
  • gnutls-devel is earlier than 0:2.8.5-18.el6
  • AND gnutls-devel is signed with Red Hat redhatrelease2 key
  • gnutls-guile is earlier than 0:2.8.5-18.el6
  • AND gnutls-guile is signed with Red Hat redhatrelease2 key
  • gnutls-utils is earlier than 0:2.8.5-18.el6
  • AND gnutls-utils is signed with Red Hat redhatrelease2 key
  • BACK