RLSA-2021:4451
Dashboard / Vulnerabilities / RLSA-2021:4451
RLSA-2021:4451
Summary: Moderate: gnutls and nettle security, bug fix, and enhancement update
Details: The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS. Nettle is a cryptographic library that is designed to fit easily in almost any context: In crypto toolkits for object-oriented languages, such as C++, Python, or Pike, in applications like LSH or GNUPG, or even in kernel space. The following packages have been upgraded to a later upstream version: gnutls (3.6.16). (BZ#1956783) Security Fix(es): * nettle: Remote crash in RSA decryption via manipulated ciphertext (CVE-2021-3580) * gnutls: Use after free in client key_share extension (CVE-2021-20231) * gnutls: Use after free in client_send_params in lib/ext/pre_shared_key.c (CVE-2021-20232) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Rocky Linux 8.5 Release Notes linked from the References section.
References: https://errata.rockylinux.org/RLSA-2021:4451, https://bugzilla.redhat.com/show_bug.cgi?id=1776250, https://bugzilla.redhat.com/show_bug.cgi?id=1908110, https://bugzilla.redhat.com/show_bug.cgi?id=1908334, https://bugzilla.redhat.com/show_bug.cgi?id=1922275, https://bugzilla.redhat.com/show_bug.cgi?id=1922276, https://bugzilla.redhat.com/show_bug.cgi?id=1965445, https://bugzilla.redhat.com/show_bug.cgi?id=1967983
Affected packages
Package
Name: gnutls
Purl: pkg:rpm/rocky-linux/gnutls?distro=rocky-linux-8-5-legacy&epoch=0
Affected ranges
Type: ECOSYSTEM
Events:
