exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Mandriva Linux Security Advisory 2008-227

Mandriva Linux Security Advisory 2008-227
Posted Nov 18, 2008
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2008-227-1 - Martin von Gagern found a flow in how GnuTLS versions 1.2.4 up until 2.6.1 verified certificate chains provided by a server. A malicious server could use this flaw to spoof its identity by tricking client applications that used the GnuTLS library to trust invalid certificates. It was found that the previously-published patch to correct this issue caused a regression when dealing with self-signed certificates. An updated patch that fixes the security issue and resolves the regression issue has been applied to these packages.

tags | advisory, spoof
systems | linux, mandriva
advisories | CVE-2008-4989
SHA-256 | bac14626a031686f97e9d85f053eab14d2203b73251d868c94d7cd0108d40380

Mandriva Linux Security Advisory 2008-227

Change Mirror Download

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2008:227-1
http://www.mandriva.com/security/
_______________________________________________________________________

Package : gnutls
Date : November 17, 2008
Affected: 2008.0, 2008.1, 2009.0
_______________________________________________________________________

Problem Description:

Martin von Gagern found a flow in how GnuTLS versions 1.2.4 up until
2.6.1 verified certificate chains provided by a server. A malicious
server could use this flaw to spoof its identity by tricking client
applications that used the GnuTLS library to trust invalid certificates
(CVE-2008-4989).

Update:

It was found that the previously-published patch to correct this
issue caused a regression when dealing with self-signed certificates.
An updated patch that fixes the security issue and resolves the
regression issue has been applied to these packages.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4989
http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3248
_______________________________________________________________________

Updated Packages:

Mandriva Linux 2008.0:
60f4f2fefdfd3684f3b005e62cb93ba1 2008.0/i586/gnutls-2.0.0-2.3mdv2008.0.i586.rpm
ae53d66478ff96540e2e7d5cfaadfe17 2008.0/i586/libgnutls13-2.0.0-2.3mdv2008.0.i586.rpm
a8d4971ad3262a9334012c41edaa7918 2008.0/i586/libgnutls-devel-2.0.0-2.3mdv2008.0.i586.rpm
14ac81812bcc8f7d9922780e89fed88d 2008.0/SRPMS/gnutls-2.0.0-2.3mdv2008.0.src.rpm

Mandriva Linux 2008.0/X86_64:
e2dfda8e991495ee2c7e6bbf3ccdb051 2008.0/x86_64/gnutls-2.0.0-2.3mdv2008.0.x86_64.rpm
db3b0edf267cdac277f47ecb9c126add 2008.0/x86_64/lib64gnutls13-2.0.0-2.3mdv2008.0.x86_64.rpm
60944c583e7956590b0de0e12ecf5610 2008.0/x86_64/lib64gnutls-devel-2.0.0-2.3mdv2008.0.x86_64.rpm
14ac81812bcc8f7d9922780e89fed88d 2008.0/SRPMS/gnutls-2.0.0-2.3mdv2008.0.src.rpm

Mandriva Linux 2008.1:
0e2b0eac5b884160d77fa03dfd2e629c 2008.1/i586/gnutls-2.3.0-2.3mdv2008.1.i586.rpm
1c9389e64590c22c6b05bacc9923a81b 2008.1/i586/libgnutls26-2.3.0-2.3mdv2008.1.i586.rpm
5500ee8c7cd28735b0f90d9224e244bd 2008.1/i586/libgnutls-devel-2.3.0-2.3mdv2008.1.i586.rpm
77d89efe54acc14a069c297de7939258 2008.1/SRPMS/gnutls-2.3.0-2.3mdv2008.1.src.rpm

Mandriva Linux 2008.1/X86_64:
9b99d7387db8864d84d9aae48a84cea8 2008.1/x86_64/gnutls-2.3.0-2.3mdv2008.1.x86_64.rpm
4085618c35d0d6b6c7f8d843701028f5 2008.1/x86_64/lib64gnutls26-2.3.0-2.3mdv2008.1.x86_64.rpm
83f17e48ec2e5c485141d392530df33d 2008.1/x86_64/lib64gnutls-devel-2.3.0-2.3mdv2008.1.x86_64.rpm
77d89efe54acc14a069c297de7939258 2008.1/SRPMS/gnutls-2.3.0-2.3mdv2008.1.src.rpm

Mandriva Linux 2009.0:
9ed865d219cdde7d45b648341d28c13c 2009.0/i586/gnutls-2.4.1-2.2mdv2009.0.i586.rpm
0add63a12831dbd02b27487a9212fb3b 2009.0/i586/libgnutls26-2.4.1-2.2mdv2009.0.i586.rpm
bd66e5cc9104b5903e6940f09a323002 2009.0/i586/libgnutls-devel-2.4.1-2.2mdv2009.0.i586.rpm
8deee0f243a9af49c55837c04c9ed46d 2009.0/SRPMS/gnutls-2.4.1-2.2mdv2009.0.src.rpm

Mandriva Linux 2009.0/X86_64:
3913ed2769a85f34ae08dffac3798f28 2009.0/x86_64/gnutls-2.4.1-2.2mdv2009.0.x86_64.rpm
0db8cbae6e1d5a68a9b81478b1ce5833 2009.0/x86_64/lib64gnutls26-2.4.1-2.2mdv2009.0.x86_64.rpm
ba3e74e7af95c837ace781d1995c5637 2009.0/x86_64/lib64gnutls-devel-2.4.1-2.2mdv2009.0.x86_64.rpm
8deee0f243a9af49c55837c04c9ed46d 2009.0/SRPMS/gnutls-2.4.1-2.2mdv2009.0.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iD8DBQFJIciDmqjQ0CJFipgRAvoZAJ4qsA7gdETcDLijzSqj+7Hv+Lu+wACgyRdA
+fgCgz/lBFWIsbVVMx+Z10o=
=f95i
-----END PGP SIGNATURE-----

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close