Executive Summary

Summary
Titlegnutls26 security update
Informations
NameDSA-2441First vendor Publication2012-03-25
VendorDebianLast vendor Modification2012-03-25
Severity (Vendor) N/ARevision1

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Cvss Base Score5Attack RangeNetwork
Cvss Impact Score2.9Attack ComplexityLow
Cvss Expoit Score10AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Matthew Hall discovered that GNUTLS does not properly handle truncated GenericBlockCipher structures nested inside TLS records, leading to crashes in applications using the GNUTLS library.

For the stable distribution (squeeze), this problem has been fixed in version 2.8.6-1+squeeze2.

For the unstable distribution (sid), this problem has been fixed in version 2.12.18-1 of the gnutls26 package and version 3.0.17-2 of the gnutls28 package.

We recommend that you upgrade your gnutls26 packages.

Original Source

Url : http://www.debian.org/security/2012/dsa-2441

CWE : Common Weakness Enumeration

idName
CWE-310Cryptographic Issues

CPE : Common Platform Enumeration

TypeDescriptionCount
Application92