Oval Definition:oval:org.mitre.oval:def:21828
Revision Date:2014-02-24Version:36
Title:RHSA-2010:0166: gnutls security update (Moderate)
Description:The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2010:0166
CVE-2009-2409
CVE-2009-3555
RHSA-2010:0166-01
Platform(s):CentOS Linux 5
Red Hat Enterprise Linux 5
Product(s):gnutls
Definition Synopsis
  • Redhat 5 or Centos 5 release
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • OR The operating system installed on the system is CentOS Linux 5.x
  • AND Packages section
  • gnutls-devel is earlier than 0:1.4.1-3.el5_4.8
  • OR gnutls-utils is earlier than 0:1.4.1-3.el5_4.8
  • OR gnutls is earlier than 0:1.4.1-3.el5_4.8
  • BACK