Oval Definition:oval:org.mitre.oval:def:24734
Revision Date:2014-07-21Version:10
Title:RHSA-2014:0594: gnutls security update (Important)
Description:The GnuTLS library provides support for cryptographic algorithms and forprotocols such as Transport Layer Security (TLS). The gnutls packages alsoinclude the libtasn1 library, which provides Abstract Syntax Notation One(ASN.1) parsing and structures management, and Distinguished Encoding Rules(DER) encoding and decoding functions.A flaw was found in the way GnuTLS parsed session IDs from ServerHellomessages of the TLS/SSL handshake. A malicious server could use this flawto send an excessively long session ID value, which would trigger a bufferoverflow in a connecting TLS/SSL client application using GnuTLS, causingthe client application to crash or, possibly, execute arbitrary code.(CVE-2014-3466)It was discovered that the asn1_get_bit_der() function of the libtasn1library incorrectly reported the length of ASN.1-encoded data. Speciallycrafted ASN.1 input could cause an application using libtasn1 to performan out-of-bounds access operation, causing the application to crash or,possibly, execute arbitrary code. (CVE-2014-3468)Multiple incorrect buffer boundary check issues were discovered inlibtasn1. Specially crafted ASN.1 input could cause an application usinglibtasn1 to crash. (CVE-2014-3467)Multiple NULL pointer dereference flaws were found in libtasn1'sasn1_read_value() function. Specially crafted ASN.1 input could cause anapplication using libtasn1 to crash, if the application used theaforementioned function in a certain way. (CVE-2014-3469)Red Hat would like to thank GnuTLS upstream for reporting these issues.Upstream acknowledges Joonas Kuorilehto of Codenomicon as the originalreporter of CVE-2014-3466.Users of GnuTLS are advised to upgrade to these updated packages, whichcorrect these issues. For the update to take effect, all applicationslinked to the GnuTLS or libtasn1 library must be restarted.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2014:0594
CVE-2014-3466
CVE-2014-3467
CVE-2014-3468
CVE-2014-3469
RHSA-2014:0594-00
Platform(s):CentOS Linux 5
Red Hat Enterprise Linux 5
Product(s):gnutls
Definition Synopsis
  • Redhat 5 or Centos 5 release
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • OR The operating system installed on the system is CentOS Linux 5.x
  • AND Packages section
  • gnutls is earlier than 0:1.4.1-16.el5_10
  • OR gnutls-devel is earlier than 0:1.4.1-16.el5_10
  • OR gnutls-utils is earlier than 0:1.4.1-16.el5_10
  • BACK