1. Gentoo Linux Security Advisory
| Advisory Reference | GLSA 200905-04 / gnutls |
| Release Date | May 24, 2009 |
| Latest Revision | May 24, 2009: 01 |
| Impact | normal |
| Exploitable | remote |
| Package | Vulnerable versions | Unaffected versions | Architecture(s) |
| net-libs/gnutls | < 2.6.6 | >= 2.6.6 | All supported architectures |
Related bugreports: #267774
Multiple vulnerabilities in GnuTLS might result in a Denial of Service, spoofing or the generation of invalid keys.
GnuTLS is an Open Source implementation of the TLS 1.0 and SSL 3.0 protocols.
The following vulnerabilities were found in GnuTLS:
A remote attacker could entice a user or automated system to process a specially crafted DSA certificate, possibly resulting in a Denial of Service condition. NOTE: This issue might have other unspecified impact including the execution of arbitrary code. Furthermore, a remote attacker could spoof signatures on certificates and the "gnutls-cli" application can be tricked into accepting an invalid certificate.
There is no known workaround at this time.
All GnuTLS users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync # emerge --ask --oneshot --verbose ">=net-libs/gnutls-2.6.6" |