gnutls (SL7)

Synopsis: Moderate: gnutls security update
Advisory ID: SLSA-2014:1846-1
Issue Date: 2014-11-12
CVE Numbers: CVE-2014-8564

An out-of-bounds memory write flaw was found in the way GnuTLS parsed
certain ECC (Elliptic Curve Cryptography) certificates or certificate
signing requests (CSR). A malicious user could create a specially crafted
ECC certificate or a certificate signing request that, when processed by
an application compiled against GnuTLS (for example, certtool), could
cause that application to crash or execute arbitrary code with the
permissions of the user running the application. (CVE-2014-8564)

For the update to take effect, all applications linked to the GnuTLS or
libtasn1 library must be restarted.

SL7
x86_64
gnutls-3.1.18-10.el7_0.i686.rpm
gnutls-3.1.18-10.el7_0.x86_64.rpm
gnutls-dane-3.1.18-10.el7_0.i686.rpm
gnutls-dane-3.1.18-10.el7_0.x86_64.rpm
gnutls-debuginfo-3.1.18-10.el7_0.i686.rpm
gnutls-debuginfo-3.1.18-10.el7_0.x86_64.rpm
gnutls-utils-3.1.18-10.el7_0.x86_64.rpm
gnutls-c++-3.1.18-10.el7_0.i686.rpm
gnutls-c++-3.1.18-10.el7_0.x86_64.rpm
gnutls-devel-3.1.18-10.el7_0.i686.rpm
gnutls-devel-3.1.18-10.el7_0.x86_64.rpm

– Scientific Linux Development Team