MGASA-2017-0212
Dashboard / Vulnerabilities / MGASA-2017-0212
Summary: Updated gnutls packages fix security vulnerabilities
Details: GnuTLS before 2017-02-20 has an out-of-bounds write caused by an integer overflow and heap-based buffer overflow related to the cdk_pkt_read function in opencdk/read-packet.c. This issue (which is a subset of the vendor's GNUTLS-SA-2017-3 report) is fixed in 3.5.10. (CVE-2017-7869) GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS extension with valid contents. This could lead to a crash of the GnuTLS server application. (CVE-2017-7507)
References: https://advisories.mageia.org/MGASA-2017-0212.html, https://bugs.mageia.org/show_bug.cgi?id=20417, https://lists.opensuse.org/opensuse-updates/2017-07/msg00064.html, http://www.gnutls.org/security.html#GNUTLS-SA-2017-3, http://www.gnutls.org/security.html#GNUTLS-SA-2017-4
Affected packages
Package
Name: gnutls
Purl: pkg:rpm/mageia/gnutls?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
