Synopsis: Important: gnutls security update
Advisory ID: SLSA-2014:0684-1
Issue Date: 2014-06-10
CVE Numbers: CVE-2014-3465
CVE-2014-3466
—
A flaw was found in the way GnuTLS parsed session IDs from ServerHello
messages of the TLS/SSL handshake. A malicious server could use this flaw
to send an excessively long session ID value, which would trigger a buffer
overflow in a connecting TLS/SSL client application using GnuTLS, causing
the client application to crash or, possibly, execute arbitrary code.
(CVE-2014-3466)
A NULL pointer dereference flaw was found in the way GnuTLS parsed X.509
certificates. A specially crafted certificate could cause a server or
client application using GnuTLS to crash. (CVE-2014-3465)
For the update to take effect, all applications linked to the GnuTLS
library must be restarted.
—
SL7
x86_64
gnutls-3.1.18-9.el7_0.i686.rpm
gnutls-3.1.18-9.el7_0.x86_64.rpm
gnutls-dane-3.1.18-9.el7_0.i686.rpm
gnutls-dane-3.1.18-9.el7_0.x86_64.rpm
gnutls-debuginfo-3.1.18-9.el7_0.i686.rpm
gnutls-debuginfo-3.1.18-9.el7_0.x86_64.rpm
gnutls-utils-3.1.18-9.el7_0.x86_64.rpm
gnutls-c++-3.1.18-9.el7_0.i686.rpm
gnutls-c++-3.1.18-9.el7_0.x86_64.rpm
gnutls-devel-3.1.18-9.el7_0.i686.rpm
gnutls-devel-3.1.18-9.el7_0.x86_64.rpm
– Scientific Linux Development Team