Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:1353-1

Опубликовано: 08 мая 2019
Источник: suse-cvrf

Описание

Security update for gnutls

This update for gnutls fixes to version 3.6.7 the following issues:

Security issued fixed:

  • CVE-2019-3836: Fixed an invalid pointer access via malformed TLS1.3 async messages (bsc#1130682).
  • CVE-2019-3829: Fixed a double free vulnerability in the certificate verification API (bsc#1130681).
  • CVE-2018-16868: Fixed Bleichenbacher-like side channel leakage in PKCS#1 v1.5 verification and padding oracle verification (bsc#1118087)

Non-security issue fixed:

  • Update gnutls to support TLS 1.3 (fate#327114)

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.0
gnutls-3.6.7-lp150.9.1
gnutls-guile-3.6.7-lp150.9.1
libgnutls-dane-devel-3.6.7-lp150.9.1
libgnutls-dane0-3.6.7-lp150.9.1
libgnutls-devel-3.6.7-lp150.9.1
libgnutls-devel-32bit-3.6.7-lp150.9.1
libgnutls30-3.6.7-lp150.9.1
libgnutls30-32bit-3.6.7-lp150.9.1
libgnutlsxx-devel-3.6.7-lp150.9.1
libgnutlsxx28-3.6.7-lp150.9.1

Описание

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.


Затронутые продукты
openSUSE Leap 15.0:gnutls-3.6.7-lp150.9.1
openSUSE Leap 15.0:gnutls-guile-3.6.7-lp150.9.1
openSUSE Leap 15.0:libgnutls-dane-devel-3.6.7-lp150.9.1
openSUSE Leap 15.0:libgnutls-dane0-3.6.7-lp150.9.1

Ссылки

Описание

A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.


Затронутые продукты
openSUSE Leap 15.0:gnutls-3.6.7-lp150.9.1
openSUSE Leap 15.0:gnutls-guile-3.6.7-lp150.9.1
openSUSE Leap 15.0:libgnutls-dane-devel-3.6.7-lp150.9.1
openSUSE Leap 15.0:libgnutls-dane0-3.6.7-lp150.9.1

Ссылки

Описание

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.


Затронутые продукты
openSUSE Leap 15.0:gnutls-3.6.7-lp150.9.1
openSUSE Leap 15.0:gnutls-guile-3.6.7-lp150.9.1
openSUSE Leap 15.0:libgnutls-dane-devel-3.6.7-lp150.9.1
openSUSE Leap 15.0:libgnutls-dane0-3.6.7-lp150.9.1

Ссылки