Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.882080
Kategorie:CentOS Local Security Checks
Titel:CentOS Update for gnutls CESA-2014:1846 centos7
Zusammenfassung:Check the version of gnutls
Beschreibung:Summary:
Check the version of gnutls

Vulnerability Insight:
The GnuTLS library provides support for
cryptographic algorithms and for protocols such as Transport Layer Security (TLS).
The gnutls packages also include the libtasn1 library, which provides Abstract
Syntax Notation One (ASN.1) parsing and structures management, and Distinguished
Encoding Rules (DER) encoding and decoding functions.

An out-of-bounds memory write flaw was found in the way GnuTLS parsed
certain ECC (Elliptic Curve Cryptography) certificates or certificate
signing requests (CSR). A malicious user could create a specially crafted
ECC certificate or a certificate signing request that, when processed by an
application compiled against GnuTLS (for example, certtool), could cause
that application to crash or execute arbitrary code with the permissions of
the user running the application. (CVE-2014-8564)

Red Hat would like to thank GnuTLS upstream for reporting this issue.
Upstream acknowledges Sean Burford as the original reporter.

All gnutls users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all applications linked to the GnuTLS or libtasn1 library must
be restarted.

Affected Software/OS:
gnutls on CentOS 7

Solution:
Please install the updated packages.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2014-8564
RedHat Security Advisories: RHSA-2014:1846
http://rhn.redhat.com/errata/RHSA-2014-1846.html
http://secunia.com/advisories/59991
http://secunia.com/advisories/62284
http://secunia.com/advisories/62294
SuSE Security Announcement: openSUSE-SU-2014:1472 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-11/msg00084.html
http://www.ubuntu.com/usn/USN-2403-1
CopyrightCopyright (C) 2014 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.