First published: Mon Mar 04 2013(Updated: )
The GnuTLS library provides support for cryptographic algorithms and for<br>protocols such as Transport Layer Security (TLS).<br>It was discovered that GnuTLS leaked timing information when decrypting<br>TLS/SSL protocol encrypted records when CBC-mode cipher suites were used.<br>A remote attacker could possibly use this flaw to retrieve plain text from<br>the encrypted packets by using a TLS/SSL server as a padding oracle.<br>(CVE-2013-1619)<br>Users of GnuTLS are advised to upgrade to these updated packages, which<br>contain a backported patch to correct this issue. For the update to take<br>effect, all applications linked to the GnuTLS library must be restarted,<br>or the system rebooted.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/gnutls | <2.8.5-10.el6_4.1 | 2.8.5-10.el6_4.1 |
redhat/gnutls | <2.8.5-10.el6_4.1 | 2.8.5-10.el6_4.1 |
redhat/gnutls-debuginfo | <2.8.5-10.el6_4.1 | 2.8.5-10.el6_4.1 |
redhat/gnutls-debuginfo | <2.8.5-10.el6_4.1 | 2.8.5-10.el6_4.1 |
redhat/gnutls-devel | <2.8.5-10.el6_4.1 | 2.8.5-10.el6_4.1 |
redhat/gnutls-devel | <2.8.5-10.el6_4.1 | 2.8.5-10.el6_4.1 |
redhat/gnutls-guile | <2.8.5-10.el6_4.1 | 2.8.5-10.el6_4.1 |
redhat/gnutls-guile | <2.8.5-10.el6_4.1 | 2.8.5-10.el6_4.1 |
redhat/gnutls-utils | <2.8.5-10.el6_4.1 | 2.8.5-10.el6_4.1 |
redhat/gnutls-utils | <2.8.5-10.el6_4.1 | 2.8.5-10.el6_4.1 |
redhat/gnutls | <1.4.1-10.el5_9.1 | 1.4.1-10.el5_9.1 |
redhat/gnutls | <1.4.1-10.el5_9.1 | 1.4.1-10.el5_9.1 |
redhat/gnutls-debuginfo | <1.4.1-10.el5_9.1 | 1.4.1-10.el5_9.1 |
redhat/gnutls-debuginfo | <1.4.1-10.el5_9.1 | 1.4.1-10.el5_9.1 |
redhat/gnutls-devel | <1.4.1-10.el5_9.1 | 1.4.1-10.el5_9.1 |
redhat/gnutls-devel | <1.4.1-10.el5_9.1 | 1.4.1-10.el5_9.1 |
redhat/gnutls-utils | <1.4.1-10.el5_9.1 | 1.4.1-10.el5_9.1 |
redhat/gnutls-utils | <1.4.1-10.el5_9.1 | 1.4.1-10.el5_9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.