Contact | Site en Français               

 


 

Vulnerabilities & Threats

 
  VUPEN Security Advisories
  Linux Security Advisories

  Malware Advisories

  Security Research
  Threat Watch Blog
  Zero-Day Monitor
  Search Engine
  Mailing List & RSS
 
   

>> Mandriva Security Update Fixes GnuTLS RSA Key Handling Signature Forgery Issue

Title : Mandriva Security Update Fixes GnuTLS RSA Key Handling Signature Forgery Issue
VUPEN ID : VUPEN/ADV-2006-3726
CVE ID : CVE-2006-4790
Rated as : Low Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2006-09-21


Technical Description    Receive VUPEN Security alerts in a Text format  Receive VUPEN Security alerts in a PDF format  Receive VUPEN Security alerts in an XML format 

Mandriva has released updated packages to address a vulnerability identified in GnuTLS. This flaw could be exploited by attackers to forge signatures. For additional information, see : VUPEN/ADV-2006-3635

Affected Products

Mandriva Linux 2006.0
Corporate 4.0

Solution

Upgrade the affected packages :

Mandriva Linux 2006.0:
7cb7aa3309af51dc44ca8bc9f855bb9b 2006.0/i586/gnutls-1.0.25-2.2.20060mdk.i586.rpm
e30b5de1b0500830cfbcfbb7a845967d 2006.0/i586/libgnutls11-1.0.25-2.2.20060mdk.i586.rpm
ddbe8a9d665b50a4614fee5251a8dc39 2006.0/i586/libgnutls11-devel-1.0.25-2.2.20060mdk.i586.rpm
aea1556e219f37a6f4be8dadce721830 2006.0/SRPMS/gnutls-1.0.25-2.2.20060mdk.src.rpm

Mandriva Linux 2006.0/X86_64:
bd9f806eb2319b5d258d142154011650 2006.0/x86_64/gnutls-1.0.25-2.2.20060mdk.x86_64.rpm
b8046dacc5e4fd5cd11acd7139fba8d9 2006.0/x86_64/lib64gnutls11-1.0.25-2.2.20060mdk.x86_64.rpm
f26c571f9379dcae4efe5ccb5ddd1bce 2006.0/x86_64/lib64gnutls11-devel-1.0.25-2.2.20060mdk.x86_64.rpm
e30b5de1b0500830cfbcfbb7a845967d 2006.0/x86_64/libgnutls11-1.0.25-2.2.20060mdk.i586.rpm
ddbe8a9d665b50a4614fee5251a8dc39 2006.0/x86_64/libgnutls11-devel-1.0.25-2.2.20060mdk.i586.rpm
aea1556e219f37a6f4be8dadce721830 2006.0/SRPMS/gnutls-1.0.25-2.2.20060mdk.src.rpm

Corporate 4.0:
a2254e8a31891b8bcc609f3cf13c62bb corporate/4.0/i586/gnutls-1.0.25-2.2.20060mlcs4.i586.rpm
41b00f4035f895b1e7b51522d1b31342 corporate/4.0/i586/libgnutls11-1.0.25-2.2.20060mlcs4.i586.rpm
2e74d9730bb73ec4cd4ccd584bd184b9 corporate/4.0/i586/libgnutls11-devel-1.0.25-2.2.20060mlcs4.i586.rpm
1e1ff2a8e7eabe7d152c98076f564476 corporate/4.0/SRPMS/gnutls-1.0.25-2.2.20060mlcs4.src.rpm

Corporate 4.0/X86_64:
05843e5fd72d31c80c5d8218cf18d812 corporate/4.0/x86_64/gnutls-1.0.25-2.2.20060mlcs4.x86_64.rpm
112708823292a1f1ca17fa68daac8373 corporate/4.0/x86_64/lib64gnutls11-1.0.25-2.2.20060mlcs4.x86_64.rpm
a0eaae0c87a0a56ef69a11c8db598fb8 corporate/4.0/x86_64/lib64gnutls11-devel-1.0.25-2.2.20060mlcs4.x86_64.rpm
41b00f4035f895b1e7b51522d1b31342 corporate/4.0/x86_64/libgnutls11-1.0.25-2.2.20060mlcs4.i586.rpm
2e74d9730bb73ec4cd4ccd584bd184b9 corporate/4.0/x86_64/libgnutls11-devel-1.0.25-2.2.20060mlcs4.i586.rpm
1e1ff2a8e7eabe7d152c98076f564476 corporate/4.0/SRPMS/gnutls-1.0.25-2.2.20060mlcs4.src.rpm

References

http://www.vupen.com/english/advisories/2006/3726
http://archives.mandrivalinux.com/security-announce/2006-09/msg00009.php

ChangeLog

2006-09-21 : Initial release

Vulnerability Management

Subscribe to VUPEN VNS and receive real-time alerts when new advisories or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form.

 

Vulnerability Alerting

Free 14-Day Trial

 
  Latest News

 

  >> 2009-07-06

     

  Microsoft Windows 0-Day
  Flaw Exploited in the Wild


  >> 2009-06-10

     

  VUPEN Security Research
  Discovered Critical Flaws
  in Adobe Acrobat and MS

  Office Word


  >> 2009-06-02

     

  VUPEN Security Research
  Discovered Critical Flaws
  in ACDSee Products


  >> 2009-05-22

     

  VUPEN Discovered Two
  Critical Vulnerabilities in
  Novell GroupWise 8 / 7

 

 

More Informations    
    








Copyright 2003-2009 © VUPEN.COM - Privacy Policy