MDVSA-2008:227-1
- Package name
- gnutls
- Date
- 2008-11-17
- Advisory ID
- MDVSA-2008:227-1
- Affected versions
- 2009.0 x86_64 , 2008.0 i586 , 2009.0 i586 , 2008.0 x86_64 , 2008.1 x86_64 , 2008.1 i586
Problem description
Martin von Gagern found a flow in how GnuTLS versions 1.2.4 up until
2.6.1 verified certificate chains provided by a server. A malicious
server could use this flaw to spoof its identity by tricking client
applications that used the GnuTLS library to trust invalid certificates
(CVE-2008-4989).
Update:
It was found that the previously-published patch to correct this
issue caused a regression when dealing with self-signed certificates.
An updated patch that fixes the security issue and resolves the
regression issue has been applied to these packages.
Updated packages
2009.0 x86_64
3913ed2769a85f34ae08dffac3798f28 2009.0/x86_64/gnutls-2.4.1-2.2mdv2009.0.x86_64.rpm 0db8cbae6e1d5a68a9b81478b1ce5833 2009.0/x86_64/lib64gnutls26-2.4.1-2.2mdv2009.0.x86_64.rpm ba3e74e7af95c837ace781d1995c5637 2009.0/x86_64/lib64gnutls-devel-2.4.1-2.2mdv2009.0.x86_64.rpm 8deee0f243a9af49c55837c04c9ed46d 2009.0/SRPMS/gnutls-2.4.1-2.2mdv2009.0.src.rpm
2008.0 i586
60f4f2fefdfd3684f3b005e62cb93ba1 2008.0/i586/gnutls-2.0.0-2.3mdv2008.0.i586.rpm ae53d66478ff96540e2e7d5cfaadfe17 2008.0/i586/libgnutls13-2.0.0-2.3mdv2008.0.i586.rpm a8d4971ad3262a9334012c41edaa7918 2008.0/i586/libgnutls-devel-2.0.0-2.3mdv2008.0.i586.rpm 14ac81812bcc8f7d9922780e89fed88d 2008.0/SRPMS/gnutls-2.0.0-2.3mdv2008.0.src.rpm
2009.0 i586
9ed865d219cdde7d45b648341d28c13c 2009.0/i586/gnutls-2.4.1-2.2mdv2009.0.i586.rpm 0add63a12831dbd02b27487a9212fb3b 2009.0/i586/libgnutls26-2.4.1-2.2mdv2009.0.i586.rpm bd66e5cc9104b5903e6940f09a323002 2009.0/i586/libgnutls-devel-2.4.1-2.2mdv2009.0.i586.rpm 8deee0f243a9af49c55837c04c9ed46d 2009.0/SRPMS/gnutls-2.4.1-2.2mdv2009.0.src.rpm
2008.0 x86_64
e2dfda8e991495ee2c7e6bbf3ccdb051 2008.0/x86_64/gnutls-2.0.0-2.3mdv2008.0.x86_64.rpm db3b0edf267cdac277f47ecb9c126add 2008.0/x86_64/lib64gnutls13-2.0.0-2.3mdv2008.0.x86_64.rpm 60944c583e7956590b0de0e12ecf5610 2008.0/x86_64/lib64gnutls-devel-2.0.0-2.3mdv2008.0.x86_64.rpm 14ac81812bcc8f7d9922780e89fed88d 2008.0/SRPMS/gnutls-2.0.0-2.3mdv2008.0.src.rpm
2008.1 x86_64
9b99d7387db8864d84d9aae48a84cea8 2008.1/x86_64/gnutls-2.3.0-2.3mdv2008.1.x86_64.rpm 4085618c35d0d6b6c7f8d843701028f5 2008.1/x86_64/lib64gnutls26-2.3.0-2.3mdv2008.1.x86_64.rpm 83f17e48ec2e5c485141d392530df33d 2008.1/x86_64/lib64gnutls-devel-2.3.0-2.3mdv2008.1.x86_64.rpm 77d89efe54acc14a069c297de7939258 2008.1/SRPMS/gnutls-2.3.0-2.3mdv2008.1.src.rpm
2008.1 i586
0e2b0eac5b884160d77fa03dfd2e629c 2008.1/i586/gnutls-2.3.0-2.3mdv2008.1.i586.rpm 1c9389e64590c22c6b05bacc9923a81b 2008.1/i586/libgnutls26-2.3.0-2.3mdv2008.1.i586.rpm 5500ee8c7cd28735b0f90d9224e244bd 2008.1/i586/libgnutls-devel-2.3.0-2.3mdv2008.1.i586.rpm 77d89efe54acc14a069c297de7939258 2008.1/SRPMS/gnutls-2.3.0-2.3mdv2008.1.src.rpm
