Bug 847484 (CVE-2013-4466) - VUL-1: CVE-2013-4466: gnutls: gnutls 3.1.x and 3.2.x overflow in libdane
Summary: VUL-1: CVE-2013-4466: gnutls: gnutls 3.1.x and 3.2.x overflow in libdane
Status: RESOLVED FIXED
Alias: CVE-2013-4466
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-10-24 14:10 UTC by Marcus Meissner
Modified: 2013-10-29 09:44 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2013-10-24 14:10:37 UTC
via GNUTLS advisory http://www.gnutls.org/security.html#GNUTLS-SA-2013-3

GNUTLS-SA-2013-3
Denial of service
This vulnerability affects the DANE library of gnutls 3.1.x and gnutls
3.2.x. A server that returns more 4 DANE entries could corrupt the memory
of a requesting client.  Recommendation: Upgrade to the latest gnutls
version (3.1.15 or 3.2.5)

Commit for 3.1:
https://gitorious.org/gnutls/gnutls/commit/916deedf41604270ac398314809e8377476433db

Commit for 3.2:
https://gitorious.org/gnutls/gnutls/commit/ed51e5e53cfbab3103d6b7b85b7ba4515e4f30c3
Comment 1 Marcus Meissner 2013-10-24 14:11:12 UTC
only openSUSE 13.1 and Factory have 3.1.x or 3.2.x., olders have 3.0 and older.
Comment 2 Swamp Workflow Management 2013-10-24 22:00:22 UTC
bugbot adjusting priority
Comment 3 Shawn Chang 2013-10-25 03:39:31 UTC
CVE-2013-4466
Comment 4 Shawn Chang 2013-10-25 04:42:01 UTC
(In reply to comment #1)
> only openSUSE 13.1 and Factory have 3.1.x or 3.2.x., olders have 3.0 and older.
>
Submit requests to openSUSE 13.1 and Factory already. Submit request ids: 204769, 204770
Comment 5 Bernhard Wiedemann 2013-10-25 05:00:10 UTC
This is an autogenerated message for OBS integration:
This bug (847484) was mentioned in
https://build.opensuse.org/request/show/204769 13.1 / gnutls
Comment 6 Shawn Chang 2013-10-29 07:58:52 UTC
Upgrade to 3.2.5: created request id 205068. Disable ECC at default.
Comment 7 Marcus Meissner 2013-10-29 09:44:21 UTC
fixed in 13.1 before GA, so done