Moderate CentOS gnutls Security Update

Metadata

medium
5.0
gnutls-3.1.18-10.el7_0.i686.rpm, gnutls-3.1.18-10.el7_0.src.rpm, gnutls-3.1.18-10.el7_0.x86_64.rpm, gnutls-c++-3.1.18-10.el7_0.i686.rpm, gnutls-c++-3.1.18-10.el7_0.x86_64.rpm, gnutls-dane-3.1.18-10.el7_0.i686.rpm, gnutls-dane-3.1.18-10.el7_0.x86_64.rpm, gnutls-devel-3.1.18-10.el7_0.i686.rpm, gnutls-devel-3.1.18-10.el7_0.x86_64.rpm, gnutls-utils-3.1.18-10.el7_0.x86_64.rpm
CVE-2014-8564
rhn.redhat.com, lists.centos.org
2014-11-12
2017-07-27 19:08
CVE-2014-8564 gnutls28
CVE-2014-8564 gnutls26
CVE-2014-8564
2017-04-01 19:08
2017-01-05 20:12

Description


Updated gnutls packages that fix one security issue are now available for
Red Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having Moderate security
impact. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available from the CVE link in the
References section.

The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS). The gnutls packages also
include the libtasn1 library, which provides Abstract Syntax Notation One
(ASN.1) parsing and structures management, and Distinguished Encoding Rules
(DER) encoding and decoding functions.

An out-of-bounds memory write flaw was found in the way GnuTLS parsed
certain ECC (Elliptic Curve Cryptography) certificates or certificate
signing requests (CSR). A malicious user could create a specially crafted
ECC certificate or a certificate signing request that, when processed by an
application compiled against GnuTLS (for example, certtool), could cause
that application to crash or execute arbitrary code with the permissions of
the user running the application. (CVE-2014-8564)

Red Hat would like to thank GnuTLS upstream for reporting this issue.
Upstream acknowledges Sean Burford as the original reporter.

All gnutls users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all applications linked to the GnuTLS or libtasn1 library must
be restarted.
Please see https://www.redhat.com/footer/terms-of-use.html

Am I vulnerable?

The constraints below list the versions that this vulnerability is patched in, and versions that are unaffected. If a patch is ready but unrealeased, then it is pending.

Or, you can just let us figure it out for you! Appcanary continously monitor your installed packages, and tell you if any of them are vulnerable.

Sign up for monitoring

Affected package information

Release Package Patched in
7 gnutls gnutls-3.1.18-10.el7_0.i686.rpm
gnutls gnutls-3.1.18-10.el7_0.src.rpm
gnutls gnutls-3.1.18-10.el7_0.x86_64.rpm
gnutls-c++ gnutls-c++-3.1.18-10.el7_0.i686.rpm
gnutls-c++ gnutls-c++-3.1.18-10.el7_0.x86_64.rpm
gnutls-dane gnutls-dane-3.1.18-10.el7_0.i686.rpm
gnutls-dane gnutls-dane-3.1.18-10.el7_0.x86_64.rpm
gnutls-devel gnutls-devel-3.1.18-10.el7_0.i686.rpm
gnutls-devel gnutls-devel-3.1.18-10.el7_0.x86_64.rpm
gnutls-utils gnutls-utils-3.1.18-10.el7_0.x86_64.rpm