![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.871850 |
Category: | Red Hat Local Security Checks |
Title: | RedHat Update for gnutls RHSA-2017:2292-01 |
Summary: | The remote host is missing an update for the 'gnutls'; package(s) announced via the referenced advisory. |
Description: | Summary: The remote host is missing an update for the 'gnutls' package(s) announced via the referenced advisory. Vulnerability Insight: The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS. The following packages have been upgraded to a later upstream version: gnutls (3.3.26). (BZ#1378373) Security Fix(es): * A double-free flaw was found in the way GnuTLS parsed certain X.509 certificates with Proxy Certificate Information extension. An attacker could create a specially-crafted certificate which, when processed by an application compiled against GnuTLS, could cause that application to crash. (CVE-2017-5334) * Multiple flaws were found in the way gnutls processed OpenPGP certificates. An attacker could create specially crafted OpenPGP certificates which, when parsed by gnutls, would cause it to crash. (CVE-2017-5335, CVE-2017-5336, CVE-2017-5337, CVE-2017-7869) * A null pointer dereference flaw was found in the way GnuTLS processed ClientHello messages with status_request extension. A remote attacker could use this flaw to cause an application compiled with GnuTLS to crash. (CVE-2017-7507) * A flaw was found in the way GnuTLS validated certificates using OCSP responses. This could falsely report a certificate as valid under certain circumstances. (CVE-2016-7444) The CVE-2017-7507 issue was discovered by Hubert Kario (Red Hat QE BaseOS Security team). Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.4 Release Notes linked from the References section. Affected Software/OS: gnutls on Red Hat Enterprise Linux Server (v. 7) Solution: Please Install the Updated Packages. CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2016-7444 BugTraq ID: 92893 http://www.securityfocus.com/bid/92893 https://lists.gnupg.org/pipermail/gnutls-devel/2016-September/008146.html RedHat Security Advisories: RHSA-2017:2292 https://access.redhat.com/errata/RHSA-2017:2292 SuSE Security Announcement: openSUSE-SU-2017:0386 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00005.html Common Vulnerability Exposure (CVE) ID: CVE-2017-5334 BugTraq ID: 95370 http://www.securityfocus.com/bid/95370 https://security.gentoo.org/glsa/201702-04 http://www.openwall.com/lists/oss-security/2017/01/10/7 http://www.openwall.com/lists/oss-security/2017/01/11/4 http://www.securitytracker.com/id/1037576 Common Vulnerability Exposure (CVE) ID: CVE-2017-5335 BugTraq ID: 95374 http://www.securityfocus.com/bid/95374 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=337 RedHat Security Advisories: RHSA-2017:0574 http://rhn.redhat.com/errata/RHSA-2017-0574.html Common Vulnerability Exposure (CVE) ID: CVE-2017-5336 BugTraq ID: 95377 http://www.securityfocus.com/bid/95377 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=340 Common Vulnerability Exposure (CVE) ID: CVE-2017-5337 BugTraq ID: 95372 http://www.securityfocus.com/bid/95372 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=338 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=346 Common Vulnerability Exposure (CVE) ID: CVE-2017-7507 99102 http://www.securityfocus.com/bid/99102 DSA-3884 http://www.debian.org/security/2017/dsa-3884 RHSA-2017:2292 https://www.gnutls.org/security.html#GNUTLS-SA-2017-4 Common Vulnerability Exposure (CVE) ID: CVE-2017-7869 BugTraq ID: 97040 http://www.securityfocus.com/bid/97040 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=420 https://gitlab.com/gnutls/gnutls/commit/51464af713d71802e3c6d5ac15f1a95132a354fe |
Copyright | Copyright (C) 2017 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |