Oval Definition:oval:com.redhat.rhsa:def:20172292
Revision Date:2017-08-01Version:640
Title:RHSA-2017:2292: gnutls security, bug fix, and enhancement update (Moderate)
Description:The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.

  • The following packages have been upgraded to a later upstream version: gnutls (3.3.26). (BZ#1378373)

    Security Fix(es):

  • A double-free flaw was found in the way GnuTLS parsed certain X.509 certificates with Proxy Certificate Information extension. An attacker could create a specially-crafted certificate which, when processed by an application compiled against GnuTLS, could cause that application to crash. (CVE-2017-5334)

  • Multiple flaws were found in the way gnutls processed OpenPGP certificates. An attacker could create specially crafted OpenPGP certificates which, when parsed by gnutls, would cause it to crash. (CVE-2017-5335, CVE-2017-5336, CVE-2017-5337, CVE-2017-7869)

  • A null pointer dereference flaw was found in the way GnuTLS processed ClientHello messages with status_request extension. A remote attacker could use this flaw to cause an application compiled with GnuTLS to crash. (CVE-2017-7507)

  • A flaw was found in the way GnuTLS validated certificates using OCSP responses. This could falsely report a certificate as valid under certain circumstances. (CVE-2016-7444)

    The CVE-2017-7507 issue was discovered by Hubert Kario (Red Hat QE BaseOS Security team).

    Additional Changes:

    For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.4 Release Notes linked from the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2016-7444
    CVE-2017-5334
    CVE-2017-5335
    CVE-2017-5336
    CVE-2017-5337
    CVE-2017-7507
    CVE-2017-7869
    RHSA-2017:2292
    RHSA-2017:2292-01
    Platform(s):Red Hat Enterprise Linux 7
    Red Hat Enterprise Linux 7 (please do not use for >= RHEL-7.5)
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • gnutls is earlier than 0:3.3.26-9.el7
  • AND gnutls is signed with Red Hat redhatrelease2 key
  • gnutls-c++ is earlier than 0:3.3.26-9.el7
  • AND gnutls-c++ is signed with Red Hat redhatrelease2 key
  • gnutls-dane is earlier than 0:3.3.26-9.el7
  • AND gnutls-dane is signed with Red Hat redhatrelease2 key
  • gnutls-devel is earlier than 0:3.3.26-9.el7
  • AND gnutls-devel is signed with Red Hat redhatrelease2 key
  • gnutls-utils is earlier than 0:3.3.26-9.el7
  • AND gnutls-utils is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 7 Client is installed
  • OR Red Hat Enterprise Linux 7 Server is installed
  • OR Red Hat Enterprise Linux 7 Workstation is installed
  • OR Red Hat Enterprise Linux 7 ComputeNode is installed
  • AND Package Information
  • gnutls-c++ is earlier than 0:3.3.26-9.el7
  • AND gnutls-c++ is signed with Red Hat redhatrelease2 key
  • OR
  • gnutls-devel is earlier than 0:3.3.26-9.el7
  • AND gnutls-devel is signed with Red Hat redhatrelease2 key
  • OR
  • gnutls-utils is earlier than 0:3.3.26-9.el7
  • AND gnutls-utils is signed with Red Hat redhatrelease2 key
  • OR
  • gnutls is earlier than 0:3.3.26-9.el7
  • AND gnutls is signed with Red Hat redhatrelease2 key
  • OR
  • gnutls-dane is earlier than 0:3.3.26-9.el7
  • AND gnutls-dane is signed with Red Hat redhatrelease2 key
  • BACK