Updated gnutls packages fix security vulnerability
Publication date: 28 Sep 2016Modification date: 28 Sep 2016
Type: security
Affected Mageia releases : 5
CVE: CVE-2016-7444
Description
An issue was found in certificate validation using OCSP responses caused by not verifying the serial length, which can falsely report a certificate as valid (CVE-2016-7444).
References
- https://bugs.mageia.org/show_bug.cgi?id=19358
- http://gnutls.org/security.html#GNUTLS-SA-2016-3
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/R3BHGPTCK63HOFYABBXNV567ESVRRKQD/
- http://openwall.com/lists/oss-security/2016/09/18/7
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7444
SRPMS
5/core
- gnutls-3.2.21-1.2.mga5