Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Patches » RHSA-2014:0247-01

Overview

Id RHSA-2014:0247-01
Name Red Hat 2014:0247-01 RHSA Important: gnutls security update for RHEL 5 x86_64
Vendor Name red_hat
Product None
Content Type Critical Critical
Language(s)
Operating System(s) Linux 
Released On 03 Mar 2014 12:00:00

RHSA-2014:0247-01

Red Hat 2014:0247-01 RHSA Important: gnutls security update for RHEL 5 x86_64

Vendor Name

red_hat

Product

None

Released On

03 Mar 2014 12:00:00

Url

https://rhn.redhat.com/errata/RHSA-2014-0247.html

Description

LSAC(v2)
The GnuTLS library provides support for cryptographic algorithms and for protocols such as Transport Layer Security (TLS). It was discovered that GnuTLS did not correctly handle certain errors that could occur during the verification of an X.509 certificate, causing it to incorrectly report a successful verification. An attacker could use this flaw to create a specially crafted certificate that could be accepted by GnuTLS as valid for a site chosen by the attacker. (CVE-2014-0092) A flaw was found in the way GnuTLS handled version 1 X.509 certificates. An attacker able to obtain a version 1 certificate from a trusted certificate authority could use this flaw to issue certificates for other sites that would be accepted by GnuTLS as valid. (CVE-2009-5138) The CVE-2014-0092 issue was discovered by Nikos Mavrogiannopoulos of the Red Hat Security Technologies Team. Users of GnuTLS are advised to upgrade to these updated packages, which correct these issues. For the update to take effect, all applications linked to the GnuTLS library must be restarted.

Related Resources

Related Vulnerabilities

None

Related Patches

Superseded Patches

None


Last Updated: 27 May 2016 11:18:32