[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2013-0588 -- Oracle gnutls

ID: oval:org.secpod.oval:def:1500006Date: (C)2013-03-20   (M)2023-12-07
Class: PATCHFamily: unix




Updated gnutls packages that fix one security issue are now available forRed Hat Enterprise Linux 5 and 6.The Red Hat Security Response Team has rated this update as having moderatesecurity impact. A Common Vulnerability Scoring System base score,which gives a detailed severity rating, is available from the CVE link inthe References section. The GnuTLS library provides support for cryptographic algorithms and forprotocols such as Transport Layer Security .It was discovered that GnuTLS leaked timing information when decryptingTLS/SSL protocol encrypted records when CBC-mode cipher suites were used.A remote attacker could possibly use this flaw to retrieve plain text fromthe encrypted packets by using a TLS/SSL server as a padding oracle.Users of GnuTLS are advised to upgrade to these updated packages, whichcontain a backported patch to correct this issue. For the update to takeeffect, all applications linked to the GnuTLS library must be restarted,or the system rebooted.

Platform:
Oracle Linux 6
Product:
gnutls
Reference:
ELSA-2013-0588
CVE-2013-1619
CVE    1
CVE-2013-1619
CPE    120
cpe:/a:gnu:gnutls:2.0.4
cpe:/a:gnu:gnutls:2.4.0
cpe:/a:gnu:gnutls:2.0.3
cpe:/a:gnu:gnutls:2.0.2
...

© SecPod Technologies