Rapid7 Vulnerability & Exploit Database

RHSA-2008:0489: gnutls security update

Back to Search

RHSA-2008:0489: gnutls security update

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
05/21/2008
Created
07/25/2018
Added
05/21/2008
Modified
07/04/2017

Description

The GnuTLS Library provides support for cryptographic algorithms andprotocols such as TLS. GnuTLS includes libtasn1, a library developed forASN.1 structures management that includes DER encoding and decoding.Flaws were found in the way GnuTLS handles malicious client connections. Amalicious remote client could send a specially crafted request to a serviceusing GnuTLS that could cause the service to crash. (CVE-2008-1948,CVE-2008-1949, CVE-2008-1950)We believe it is possible to leverage the flaw CVE-2008-1948 to executearbitrary code but have been unable to prove this at the time of releasingthis advisory. Red Hat Enterprise Linux 5 includes applications, such asCUPS, that would be directly vulnerable to any such an exploit, however.Consequently, we have assigned it critical severity.Users of GnuTLS are advised to upgrade to these updated packages, whichcontain a backported patch that corrects these issues.

Solution(s)

  • redhat-upgrade-gnutls
  • redhat-upgrade-gnutls-devel
  • redhat-upgrade-gnutls-utils

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;