Novell is now a part of Micro Focus

My Favorites

Close

Please to see your favorites.

GnuTLS Security update for Novell Open Enterprise Server 2 SP3.

This document (7015302) is provided subject to the disclaimer at the end of this document.

Environment

SUSE Linux Enterprise Server 10 Service Pack 4 (SLES 10 SP4)
Novell Open Enterprise Server 2 (OES 2) Linux Support Pack 3

Situation

SUSE Linux Enterprise Server 10 SP4 General support has ended on 31 July 2013.
Novell Open Enterprise Server 2 SP3 General support has ended on  31 July 2013.

A number of GnuTLS related Security Vulnerabilities were reported.

Due to the current extended support status for Novell Open Enterprise Server 2 SP3, the Novell and SUSE teams have closely collaborated to make these fix available for Novell OES2 SP3 customers.

Resolution

The oes2sp3-gnutls-8896 patch containing the mentioned fixes for SLES 10 SP4 is released through the public OES2 SP3 patch repositories on 30 June 2014.

GnuTLS has been patched to ensure proper parsing of session ids during the TLS/SSL handshake. Additionally three issues inherited from libtasn1 have been fixed.

Further information is available at http://www.gnutls.org/security.html#GNUTLS-SA-2014-3

These security issues have been fixed:

  • Possible memory corruption during connect (CVE-2014-3466)
  • Multiple boundary check issues could allow DoS (CVE-2014-3467)
  • asn1_get_bit_der() can return negative bit length (CVE-2014-3468)
  • Possible DoS by NULL pointer dereference (CVE-2014-3469)

Security Issues:

Cause

Multiple GnuTLS related security vulnerabilities.

Disclaimer

This Support Knowledgebase provides a valuable tool for NetIQ/Novell/SUSE customers and parties interested in our products and solutions to acquire information, ideas and learn from one another. Materials are provided for informational, personal or non-commercial use within your organization and are presented "AS IS" WITHOUT WARRANTY OF ANY KIND.

  • Document ID:7015302
  • Creation Date:01-JUL-14
  • Modified Date:01-JUL-14
    • NovellOpen Enterprise Server
    • SUSESUSE Linux Enterprise Server

Did this document solve your problem? Provide Feedback