First published: Thu Mar 25 2010(Updated: )
The GnuTLS library provides support for cryptographic algorithms and for<br>protocols such as Transport Layer Security (TLS).<br>A flaw was found in the way the TLS/SSL (Transport Layer Security/Secure<br>Sockets Layer) protocols handled session renegotiation. A man-in-the-middle<br>attacker could use this flaw to prefix arbitrary plain text to a client's<br>session (for example, an HTTPS connection to a website). This could force<br>the server to process an attacker's request as if authenticated using the<br>victim's credentials. This update addresses this flaw by implementing the<br>TLS Renegotiation Indication Extension, as defined in RFC 5746.<br>(CVE-2009-3555)<br>Refer to the following Knowledgebase article for additional details about<br>the CVE-2009-3555 flaw: <a href="http://kbase.redhat.com/faq/docs/DOC-20491" target="_blank">http://kbase.redhat.com/faq/docs/DOC-20491</a> A flaw was found in the way GnuTLS extracted serial numbers from X.509<br>certificates. On 64-bit big endian platforms, this flaw could cause the<br>certificate revocation list (CRL) check to be bypassed; cause various<br>GnuTLS utilities to crash; or, possibly, execute arbitrary code.<br>(CVE-2010-0731)<br>Users of GnuTLS are advised to upgrade to these updated packages, which<br>contain backported patches to correct these issues. For the update to take<br>effect, all applications linked to the GnuTLS library must be restarted, or<br>the system rebooted.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/gnutls | <1.0.20-4.el4_8.7 | 1.0.20-4.el4_8.7 |
redhat/gnutls | <1.0.20-4.el4_8.7 | 1.0.20-4.el4_8.7 |
redhat/gnutls-devel | <1.0.20-4.el4_8.7 | 1.0.20-4.el4_8.7 |
redhat/gnutls-devel | <1.0.20-4.el4_8.7 | 1.0.20-4.el4_8.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2010:0167 is classified as important.
To fix RHSA-2010:0167, update the GnuTLS package to version 1.0.20-4.el4_8.7 or newer.
RHSA-2010:0167 affects Red Hat Enterprise Linux 4 systems using the GnuTLS package.
RHSA-2010:0167 identifies a flaw in the TLS/SSL protocols handling session renegotiation.
RHSA-2010:0167 is not classified as critical, but it does pose significant security risks.