Oval Definition:oval:org.mitre.oval:def:13825
Revision Date:2014-06-30Version:20
Title:USN-809-1 -- gnutls12, gnutls13, gnutls26 vulnerabilities
Description:Moxie Marlinspike and Dan Kaminsky independently discovered that GnuTLS did not properly handle certificates with NULL characters in the certificate name. An attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications. Dan Kaminsky discovered GnuTLS would still accept certificates with MD2 hash signatures. As a result, an attacker could potentially create a malicious trusted certificate to impersonate another site. This issue only affected Ubuntu 6.06 LTS and Ubuntu 8.10. USN-678-1 fixed a vulnerability and USN-678-2 a regression in GnuTLS. The upstream patches introduced a regression when validating certain certificate chains that would report valid certificates as untrusted. This update fixes the problem, and only affected Ubuntu 6.06 LTS and Ubuntu 8.10 . In an effort to maintain a strong security stance and address all known regressions, this update deprecates X.509 validation chains using MD2 and MD5 signatures. To accomodate sites which must still use a deprected RSA-MD5 certificate, GnuTLS has been updated to stop looking when it has found a trusted intermediary certificate. This new handling of intermediary certificates is in accordance with other SSL implementations. Original advisory details: Martin von Gagern discovered that GnuTLS did not properly verify certificate chains when the last certificate in the chain was self-signed. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to view sensitive information
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2008-4989
CVE-2009-2409
CVE-2009-2730
USN-809-1
USN-809-1
Platform(s):Ubuntu 6.06
Ubuntu 8.04
Ubuntu 8.10
Ubuntu 9.04
Product(s):gnutls12
gnutls13
gnutls26
Definition Synopsis
  • Release section
  • Ubuntu 8.04 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND gnutls-doc DPKG is earlier than 2.0.4-1ubuntu2.6
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • OR Installed architecture is sparc
  • OR Installed architecture is lpia
  • AND Packages section
  • libgnutls-dev DPKG is earlier than 2.0.4-1ubuntu2.6
  • OR gnutls-bin DPKG is earlier than 2.0.4-1ubuntu2.6
  • OR libgnutlsxx13 DPKG is earlier than 2.0.4-1ubuntu2.6
  • OR libgnutls13 DPKG is earlier than 2.0.4-1ubuntu2.6
  • OR libgnutls13-dbg DPKG is earlier than 2.0.4-1ubuntu2.6
  • OR Release section
  • Ubuntu 9.04 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND gnutls-doc DPKG is earlier than 2.4.2-6ubuntu0.1
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • OR Installed architecture is sparc
  • OR Installed architecture is lpia
  • AND Packages section
  • libgnutls-dev DPKG is earlier than 2.4.2-6ubuntu0.1
  • OR libgnutls26-dbg DPKG is earlier than 2.4.2-6ubuntu0.1
  • OR libgnutls26 DPKG is earlier than 2.4.2-6ubuntu0.1
  • OR gnutls-bin DPKG is earlier than 2.4.2-6ubuntu0.1
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is sparc
  • OR Installed architecture is i386
  • OR Installed architecture is amd64
  • OR Installed architecture is powerpc
  • AND guile-gnutls DPKG is earlier than 2.4.2-6ubuntu0.1
  • OR Release section
  • Ubuntu 6.06 is installed
  • AND Supported architectures section
  • Installed architecture is sparc
  • OR Installed architecture is i386
  • OR Installed architecture is amd64
  • OR Installed architecture is powerpc
  • AND Packages section
  • libgnutls12 DPKG is earlier than 1.2.9-2ubuntu1.7
  • OR libgnutls-dev DPKG is earlier than 1.2.9-2ubuntu1.7
  • OR libgnutls12-dbg DPKG is earlier than 1.2.9-2ubuntu1.7
  • OR gnutls-bin DPKG is earlier than 1.2.9-2ubuntu1.7
  • OR Release section
  • Ubuntu 8.10 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND gnutls-doc DPKG is earlier than 2.4.1-1ubuntu0.4
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • OR Installed architecture is sparc
  • OR Installed architecture is lpia
  • AND Packages section
  • libgnutls-dev DPKG is earlier than 2.4.1-1ubuntu0.4
  • OR libgnutls26-dbg DPKG is earlier than 2.4.1-1ubuntu0.4
  • OR libgnutls26 DPKG is earlier than 2.4.1-1ubuntu0.4
  • OR gnutls-bin DPKG is earlier than 2.4.1-1ubuntu0.4
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is sparc
  • OR Installed architecture is i386
  • OR Installed architecture is amd64
  • OR Installed architecture is powerpc
  • AND guile-gnutls DPKG is earlier than 2.4.1-1ubuntu0.4
  • BACK