Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.856069
Kategorie:openSUSE Local Security Checks
Titel:openSUSE Security Advisory (SUSE-SU-2024:1271-1)
Zusammenfassung:The remote host is missing an update for the 'gnutls' package(s) announced via the SUSE-SU-2024:1271-1 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'gnutls' package(s) announced via the SUSE-SU-2024:1271-1 advisory.

Vulnerability Insight:
This update for gnutls fixes the following issues:

- CVE-2024-28834: Fixed side-channel in the deterministic ECDSA (bsc#1221746)
- CVE-2024-28835: Fixed denial of service during certificate chain verification (bsc#1221747)

Other fixes:
- jitterentropy: Release the memory of the entropy collector when
using jitterentropy with phtreads as there is also a
pre-intitization done in the main thread (bsc#1221242)

Affected Software/OS:
'gnutls' package(s) on openSUSE Leap 15.5.

Solution:
Please install the updated package(s).

CVSS Score:
4.9

CVSS Vector:
AV:N/AC:H/Au:S/C:C/I:N/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2024-28834
RHBZ#2269228
https://bugzilla.redhat.com/show_bug.cgi?id=2269228
RHSA-2024:1784
https://access.redhat.com/errata/RHSA-2024:1784
RHSA-2024:1879
https://access.redhat.com/errata/RHSA-2024:1879
RHSA-2024:1997
https://access.redhat.com/errata/RHSA-2024:1997
RHSA-2024:2044
https://access.redhat.com/errata/RHSA-2024:2044
RHSA-2024:2570
https://access.redhat.com/errata/RHSA-2024:2570
RHSA-2024:2889
https://access.redhat.com/errata/RHSA-2024:2889
http://www.openwall.com/lists/oss-security/2024/03/22/1
http://www.openwall.com/lists/oss-security/2024/03/22/2
https://access.redhat.com/security/cve/CVE-2024-28834
https://lists.gnupg.org/pipermail/gnutls-help/2024-March/004845.html
https://minerva.crocs.fi.muni.cz/
https://people.redhat.com/~hkario/marvin/
Common Vulnerability Exposure (CVE) ID: CVE-2024-28835
RHBZ#2269084
https://bugzilla.redhat.com/show_bug.cgi?id=2269084
https://access.redhat.com/security/cve/CVE-2024-28835
CopyrightCopyright (C) 2024 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.