Home / mailings [gentoo-announce] [ GLSA 201206-18 ] GnuTLS: Multiple vulnerabilities
Posted on 23 June 2012
Gentoo-announceThis is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--------------enigF0251E4FCD42B76BDB8AE010
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 201206-18
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: Normal
Title: GnuTLS: Multiple vulnerabilities
Date: June 23, 2012
Bugs: #281224, #292025, #389947, #409287
ID: 201206-18
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Multiple vulnerabilities have been found in GnuTLS, allowing a remote
attacker to perform man-in-the-middle or Denial of Service attacks.
Background
==========
GnuTLS is an Open Source implementation of the TLS 1.2 and SSL 3.0
protocols.
Affected packages
=================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-libs/gnutls < 2.12.18 >= 2.12.18
Description
===========
Multiple vulnerabilities have been found in GnuTLS:
* An error in libgnutls does not properly sanitize "