Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-6854

Опубликовано: 11 окт. 2022
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2022-6854: gnutls and nettle security, bug fix, and enhancement update (MODERATE)

gnutls [3.7.6-12]

  • fips: mark PBKDF2 with short key and output sizes non-approved
  • fips: only mark HMAC as approved in PBKDF2
  • fips: mark gnutls_key_generate with short key sizes non-approved
  • fips: fix checking on hash algorithm used in ECDSA
  • fips: preserve operation context around FIPS selftests API

[3.7.6-11]

  • Supply --with{,out}-{zlib,brotli,zstd} explicitly

[3.7.6-10]

  • Revert nettle version pinning as it doesn't work well in side-tag

[3.7.6-9]

  • Pin nettle version in Requires when compiled with FIPS

[3.7.6-8]

  • Bundle GMP to privatize memory functions
  • Disable certificate compression support by default

[3.7.6-7]

  • Update gnutls-3.7.6-cpuid-fixes.patch

[3.7.6-6]

  • Mark RSA SigVer operation approved for known modulus sizes (#2119770)
  • accelerated: clear AVX bits if it cannot be queried through XSAVE

[3.7.6-5]

  • Block DES-CBC usage in decrypting PKCS#12 bag under FIPS (#2115314)
  • sysrng: reseed source DRBG for prediction resistance

[3.7.6-4]

  • Make gnutls-cli work with KTLS for testing
  • Fix double-free in gnutls_pkcs7_verify (#2109789)

[3.7.6-3]

  • Limit input size for AES-GCM according to SP800-38D (#2108635)
  • Do not treat GPG verification errors as fatal
  • Remove gnutls-3.7.6-libgnutlsxx-const.patch

[3.7.6-2]

  • Allow enabling KTLS with config file (#2108532)

[3.7.6-1]

  • Update to gnutls 3.7.6 (#2102591)

[3.7.3-10]

  • Use only the first component of VERSION from /etc/os-release (#2076626)
  • Don't run power-on self-tests on DSA (#2076627)

nettle [3.8-3]

  • Rebuild in new side-tag

[3.8-2]

  • Bundle GMP to privatize memory functions
  • Zeroize stack allocated intermediate data

[3.8-1]

  • Update to nettle 3.8 (#2100350)

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

gnutls

3.7.6-12.el9_0

gnutls-c++

3.7.6-12.el9_0

gnutls-dane

3.7.6-12.el9_0

gnutls-devel

3.7.6-12.el9_0

gnutls-utils

3.7.6-12.el9_0

nettle

3.8-3.el9_0

nettle-devel

3.8-3.el9_0

Oracle Linux x86_64

gnutls

3.7.6-12.el9_0

gnutls-c++

3.7.6-12.el9_0

gnutls-dane

3.7.6-12.el9_0

gnutls-devel

3.7.6-12.el9_0

gnutls-utils

3.7.6-12.el9_0

nettle

3.8-3.el9_0

nettle-devel

3.8-3.el9_0

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function.

CVSS3: 7.5
redhat
почти 3 года назад

A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function.

CVSS3: 7.5
nvd
почти 3 года назад

A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function.

CVSS3: 7.5
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 7.5
debian
почти 3 года назад

A vulnerability found in gnutls. This security flaw happens because of ...