Oval Definition:oval:com.redhat.rhsa:def:20170574
Revision Date:2017-03-21Version:640
Title:RHSA-2017:0574: gnutls security, bug fix, and enhancement update (Moderate)
Description:The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.

  • The following packages have been upgraded to a later upstream version: gnutls (2.12.23). (BZ#1321112, BZ#1326073, BZ#1415682, BZ#1326389)

    Security Fix(es):

  • A denial of service flaw was found in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections form other clients. (CVE-2016-8610)

  • Multiple flaws were found in the way gnutls processed OpenPGP certificates. An attacker could create specially crafted OpenPGP certificates which, when parsed by gnutls, would cause it to crash. (CVE-2017-5335, CVE-2017-5336, CVE-2017-5337)

    Additional Changes:

    For detailed information on changes in this release, see the Red Hat Enterprise Linux 6.9 Release Notes and Red Hat Enterprise Linux 6.9 Technical Notes linked from the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2016-8610
    CVE-2017-5335
    CVE-2017-5336
    CVE-2017-5337
    RHSA-2017:0574
    RHSA-2017:0574-00
    RHSA-2017:0574-01
    RHSA-2017:0574-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • gnutls is earlier than 0:2.12.23-21.el6
  • AND gnutls is signed with Red Hat redhatrelease2 key
  • gnutls-devel is earlier than 0:2.12.23-21.el6
  • AND gnutls-devel is signed with Red Hat redhatrelease2 key
  • gnutls-guile is earlier than 0:2.12.23-21.el6
  • AND gnutls-guile is signed with Red Hat redhatrelease2 key
  • gnutls-utils is earlier than 0:2.12.23-21.el6
  • AND gnutls-utils is signed with Red Hat redhatrelease2 key
  • BACK