SUSE-SU-2017:0348-1
Dashboard / Vulnerabilities / SUSE-SU-2017:0348-1
SUSE-SU-2017:0348-1
Summary: Security update for gnutls
Details: This update for gnutls fixes the following security issues: - GnuTLS could have crashed when processing maliciously crafted OpenPGP certificates (GNUTLS-SA-2017-2, bsc#1018832, CVE-2017-5335, CVE-2017-5337, CVE-2017-5336) - GnuTLS could have falsely accepted certificates when using OCSP (GNUTLS-SA-2016-3, bsc#999646, CVE-2016-7444) - GnuTLS could have suffered from 100% CPU load DoS attacks by using SSL alert packets during the handshake (bsc#1005879, CVE-2016-8610)
References: https://www.suse.com/support/update/announcement/2017/suse-su-20170348-1/, https://bugzilla.suse.com/1005879, https://bugzilla.suse.com/1018832, https://bugzilla.suse.com/999646, https://www.suse.com/security/cve/CVE-2016-7444, https://www.suse.com/security/cve/CVE-2016-8610, https://www.suse.com/security/cve/CVE-2017-5335, https://www.suse.com/security/cve/CVE-2017-5336, https://www.suse.com/security/cve/CVE-2017-5337
Affected packages
Package
Name: gnutls
Purl: pkg:rpm/suse/gnutls&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1
Affected ranges
Type: ECOSYSTEM
Events:
