GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Sun Sep 06, 2020 1:26 am Post subject: [ GLSA 202009-01 ] GnuTLS |
|
|
Gentoo Linux Security Advisory
Title: GnuTLS: Denial of service (GLSA 202009-01)
Severity: low
Exploitable: local, remote
Date: 2020-09-06
Bug(s): #740390
ID: 202009-01
Synopsis
A flaw was found in GnuTLS, possibly allowing a Denial of Service
condition.
Background
GnuTLS is an Open Source implementation of the TLS and SSL protocols.
Affected Packages
Package: net-libs/gnutls
Vulnerable: < 3.6.15
Unaffected: >= 3.6.15
Architectures: All supported architectures
Description
It was found that GnuTLS didn’t handle “no_renegotiation” alert
properly.
Impact
A remote attacker could entice a user to connect to a malicious TLS
endpoint using an application linked against GnuTLS, possibly resulting
in a Denial of Service condition.
Workaround
There is no known workaround at this time.
Resolution
All GnuTLS users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=net-libs/gnutls-3.6.15"
|
References
CVE-2020-24659 |
|