Contact | Site en Français               

 


 

Vulnerabilities & Threats

 
  VUPEN Security Advisories
  Linux Security Advisories

  Malware Advisories

  Security Research
  Threat Watch Blog
  Zero-Day Monitor
  Search Engine
  Mailing List & RSS
 
   

>> Mandriva Security Update Fixes GnuTLS Chain Validation Vulnerability

Title : Mandriva Security Update Fixes GnuTLS Chain Validation Vulnerability
VUPEN ID : VUPEN/ADV-2008-3131
CVE ID : CVE-2008-4989
Rated as : Moderate Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2008-11-13


Technical Description    Receive VUPEN Security alerts in a Text format  Receive VUPEN Security alerts in a PDF format  Receive VUPEN Security alerts in an XML format 

A vulnerability has been identified in Mandriva, which could be exploited by attackers to bypass security checks. This issue is caused by an error in GnuTLS. For additional information, see : VUPEN/ADV-2008-3086

Affected Products

Mandriva Linux 2008.0
Mandriva Linux 2008.1
Mandriva Linux 2009.0

Solution

Upgrade the affected packages :

Mandriva Linux 2008.0:
60f4f2fefdfd3684f3b005e62cb93ba1 2008.0/i586/gnutls-2.0.0-2.3mdv2008.0.i586.rpm
ae53d66478ff96540e2e7d5cfaadfe17 2008.0/i586/libgnutls13-2.0.0-2.3mdv2008.0.i586.rpm
a8d4971ad3262a9334012c41edaa7918 2008.0/i586/libgnutls-devel-2.0.0-2.3mdv2008.0.i586.rpm
14ac81812bcc8f7d9922780e89fed88d 2008.0/SRPMS/gnutls-2.0.0-2.3mdv2008.0.src.rpm

Mandriva Linux 2008.0/X86_64:
e2dfda8e991495ee2c7e6bbf3ccdb051 2008.0/x86_64/gnutls-2.0.0-2.3mdv2008.0.x86_64.rpm
db3b0edf267cdac277f47ecb9c126add 2008.0/x86_64/lib64gnutls13-2.0.0-2.3mdv2008.0.x86_64.rpm
60944c583e7956590b0de0e12ecf5610 2008.0/x86_64/lib64gnutls-devel-2.0.0-2.3mdv2008.0.x86_64.rpm
14ac81812bcc8f7d9922780e89fed88d 2008.0/SRPMS/gnutls-2.0.0-2.3mdv2008.0.src.rpm

Mandriva Linux 2008.1:
0e2b0eac5b884160d77fa03dfd2e629c 2008.1/i586/gnutls-2.3.0-2.3mdv2008.1.i586.rpm
1c9389e64590c22c6b05bacc9923a81b 2008.1/i586/libgnutls26-2.3.0-2.3mdv2008.1.i586.rpm
5500ee8c7cd28735b0f90d9224e244bd 2008.1/i586/libgnutls-devel-2.3.0-2.3mdv2008.1.i586.rpm
77d89efe54acc14a069c297de7939258 2008.1/SRPMS/gnutls-2.3.0-2.3mdv2008.1.src.rpm

Mandriva Linux 2008.1/X86_64:
9b99d7387db8864d84d9aae48a84cea8 2008.1/x86_64/gnutls-2.3.0-2.3mdv2008.1.x86_64.rpm
4085618c35d0d6b6c7f8d843701028f5 2008.1/x86_64/lib64gnutls26-2.3.0-2.3mdv2008.1.x86_64.rpm
83f17e48ec2e5c485141d392530df33d 2008.1/x86_64/lib64gnutls-devel-2.3.0-2.3mdv2008.1.x86_64.rpm
77d89efe54acc14a069c297de7939258 2008.1/SRPMS/gnutls-2.3.0-2.3mdv2008.1.src.rpm

Mandriva Linux 2009.0:
9ed865d219cdde7d45b648341d28c13c 2009.0/i586/gnutls-2.4.1-2.2mdv2009.0.i586.rpm
0add63a12831dbd02b27487a9212fb3b 2009.0/i586/libgnutls26-2.4.1-2.2mdv2009.0.i586.rpm
bd66e5cc9104b5903e6940f09a323002 2009.0/i586/libgnutls-devel-2.4.1-2.2mdv2009.0.i586.rpm
8deee0f243a9af49c55837c04c9ed46d 2009.0/SRPMS/gnutls-2.4.1-2.2mdv2009.0.src.rpm

Mandriva Linux 2009.0/X86_64:
3913ed2769a85f34ae08dffac3798f28 2009.0/x86_64/gnutls-2.4.1-2.2mdv2009.0.x86_64.rpm
0db8cbae6e1d5a68a9b81478b1ce5833 2009.0/x86_64/lib64gnutls26-2.4.1-2.2mdv2009.0.x86_64.rpm
ba3e74e7af95c837ace781d1995c5637 2009.0/x86_64/lib64gnutls-devel-2.4.1-2.2mdv2009.0.x86_64.rpm
8deee0f243a9af49c55837c04c9ed46d 2009.0/SRPMS/gnutls-2.4.1-2.2mdv2009.0.src.rpm

References

http://www.vupen.com/english/advisories/2008/3131
http://lists.mandriva.com/security-announce/2008-11/msg00006.php
http://lists.mandriva.com/security-announce/2008-11/msg00013.php

ChangeLog

2008-11-13 : Initial release
2008-11-19 : Updated Solution

Vulnerability Management

Subscribe to VUPEN VNS and receive real-time alerts when new advisories or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form.

 

Vulnerability Alerting

Free 14-Day Trial

 
  Latest News

 

  >> 2009-07-06

     

  Microsoft Windows 0-Day
  Flaw Exploited in the Wild


  >> 2009-06-10

     

  VUPEN Security Research
  Discovered Critical Flaws
  in Adobe Acrobat and MS

  Office Word


  >> 2009-06-02

     

  VUPEN Security Research
  Discovered Critical Flaws
  in ACDSee Products


  >> 2009-05-22

     

  VUPEN Discovered Two
  Critical Vulnerabilities in
  Novell GroupWise 8 / 7

 

 

More Informations    
    








Copyright 2003-2009 © VUPEN.COM - Privacy Policy