Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.871780
Category:Red Hat Local Security Checks
Title:RedHat Update for gnutls RHSA-2017:0574-01
Summary:The remote host is missing an update for the 'gnutls'; package(s) announced via the referenced advisory.
Description:Summary:
The remote host is missing an update for the 'gnutls'
package(s) announced via the referenced advisory.

Vulnerability Insight:
The gnutls packages provide the GNU
Transport Layer Security (GnuTLS) library, which implements cryptographic
algorithms and protocols such as SSL, TLS, and DTLS.

The following packages have been upgraded to a later upstream version:
gnutls (2.12.23). (BZ#1321112, BZ#1326073, BZ#1415682, BZ#1326389)

Security Fix(es):

* A denial of service flaw was found in the way the TLS/SSL protocol
defined processing of ALERT packets during a connection handshake. A remote
attacker could use this flaw to make a TLS/SSL server consume an excessive
amount of CPU and fail to accept connections form other clients.
(CVE-2016-8610)

* Multiple flaws were found in the way gnutls processed OpenPGP
certificates. An attacker could create specially crafted OpenPGP
certificates which, when parsed by gnutls, would cause it to crash.
(CVE-2017-5335, CVE-2017-5336, CVE-2017-5337)

Additional Changes:

For detailed information on changes in this release, see the Red Hat
Enterprise Linux 6.9 Release Notes and Red Hat Enterprise Linux 6.9
Technical Notes linked from the References section.

Affected Software/OS:
gnutls on Red Hat Enterprise Linux Desktop (v. 6),
Red Hat Enterprise Linux Server (v. 6),
Red Hat Enterprise Linux Workstation (v. 6)

Solution:
Please Install the Updated Packages.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-8610
1037084
http://www.securitytracker.com/id/1037084
93841
http://www.securityfocus.com/bid/93841
DSA-3773
https://www.debian.org/security/2017/dsa-3773
FreeBSD-SA-16:35
https://security.FreeBSD.org/advisories/FreeBSD-SA-16:35.openssl.asc
RHSA-2017:0286
http://rhn.redhat.com/errata/RHSA-2017-0286.html
RHSA-2017:0574
http://rhn.redhat.com/errata/RHSA-2017-0574.html
RHSA-2017:1413
https://access.redhat.com/errata/RHSA-2017:1413
RHSA-2017:1414
https://access.redhat.com/errata/RHSA-2017:1414
RHSA-2017:1415
http://rhn.redhat.com/errata/RHSA-2017-1415.html
RHSA-2017:1658
https://access.redhat.com/errata/RHSA-2017:1658
RHSA-2017:1659
http://rhn.redhat.com/errata/RHSA-2017-1659.html
RHSA-2017:1801
https://access.redhat.com/errata/RHSA-2017:1801
RHSA-2017:1802
https://access.redhat.com/errata/RHSA-2017:1802
RHSA-2017:2493
https://access.redhat.com/errata/RHSA-2017:2493
RHSA-2017:2494
https://access.redhat.com/errata/RHSA-2017:2494
[oss-security] 20161024 CVE-2016-8610: SSL Death Alert: OpenSSL SSL/TLS SSL3_AL_WARNING undefined alert Remote DoS
http://seclists.org/oss-sec/2016/q4/224
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8610
https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=af58be768ebb690f78530f796e92b8ae5c9a4401
https://security.360.cn/cve/CVE-2016-8610/
https://security.netapp.com/advisory/ntap-20171130-0001/
https://security.paloaltonetworks.com/CVE-2016-8610
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03897en_us
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/security-alerts/cpujul2020.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Common Vulnerability Exposure (CVE) ID: CVE-2017-5335
BugTraq ID: 95374
http://www.securityfocus.com/bid/95374
https://security.gentoo.org/glsa/201702-04
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=337
http://www.openwall.com/lists/oss-security/2017/01/10/7
http://www.openwall.com/lists/oss-security/2017/01/11/4
RedHat Security Advisories: RHSA-2017:0574
RedHat Security Advisories: RHSA-2017:2292
https://access.redhat.com/errata/RHSA-2017:2292
http://www.securitytracker.com/id/1037576
SuSE Security Announcement: openSUSE-SU-2017:0386 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00005.html
Common Vulnerability Exposure (CVE) ID: CVE-2017-5336
BugTraq ID: 95377
http://www.securityfocus.com/bid/95377
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=340
Common Vulnerability Exposure (CVE) ID: CVE-2017-5337
BugTraq ID: 95372
http://www.securityfocus.com/bid/95372
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=338
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=346
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.