ALSA-2021:4451
Dashboard / Vulnerabilities / ALSA-2021:4451
ALSA-2021:4451
Summary: Moderate: gnutls and nettle security, bug fix, and enhancement update
Details: The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS. Nettle is a cryptographic library that is designed to fit easily in almost any context: In crypto toolkits for object-oriented languages, such as C++, Python, or Pike, in applications like LSH or GNUPG, or even in kernel space. The following packages have been upgraded to a later upstream version: gnutls (3.6.16). (BZ#1956783) Security Fix(es): * nettle: Remote crash in RSA decryption via manipulated ciphertext (CVE-2021-3580) * gnutls: Use after free in client key_share extension (CVE-2021-20231) * gnutls: Use after free in client_send_params in lib/ext/pre_shared_key.c (CVE-2021-20232) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
References: https://errata.almalinux.org/8/ALSA-2021-4451.html, https://vulners.com/cve/CVE-2021-20231, https://vulners.com/cve/CVE-2021-20232, https://vulners.com/cve/CVE-2021-3580
Affected packages
Package
Name: gnutls
Purl: pkg:rpm/almalinux/gnutls
Affected ranges
Type: ECOSYSTEM
Events:
