Bugzilla – Bug 999646
VUL-1: CVE-2016-7444 gnutls: Incorrect certificate validation when using OCSP responses (GNUTLS-SA-2016-3)
Last modified: 2019-05-01 17:22:52 UTC
rh#1374266 It was found an issue in certificate validation using OCSP responses caused by not verifying the serial length, which can falsely report a certificate as valid. Upstream patch: https://gitlab.com/gnutls/gnutls/commit/964632f37dfdfb914ebc5e49db4fa29af35b1de9 External References: https://www.gnutls.org/security.html https://lists.gnupg.org/pipermail/gnutls-devel/2016-September/008146.html References: https://bugzilla.redhat.com/show_bug.cgi?id=1374266 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-7444 http://seclists.org/oss-sec/2016/q3/549
bugbot adjusting priority
SUSE-SU-2017:0348-1: An update that fixes 5 vulnerabilities is now available. Category: security (important) Bug References: 1005879,1018832,999646 CVE References: CVE-2016-7444,CVE-2016-8610,CVE-2017-5335,CVE-2017-5336,CVE-2017-5337 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP2 (src): gnutls-3.2.15-16.1 SUSE Linux Enterprise Software Development Kit 12-SP1 (src): gnutls-3.2.15-16.1 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src): gnutls-3.2.15-16.1 SUSE Linux Enterprise Server 12-SP2 (src): gnutls-3.2.15-16.1 SUSE Linux Enterprise Server 12-SP1 (src): gnutls-3.2.15-16.1 SUSE Linux Enterprise Desktop 12-SP2 (src): gnutls-3.2.15-16.1 SUSE Linux Enterprise Desktop 12-SP1 (src): gnutls-3.2.15-16.1
release leap
openSUSE-SU-2017:0386-1: An update that fixes 5 vulnerabilities is now available. Category: security (important) Bug References: 1005879,1018832,999646 CVE References: CVE-2016-7444,CVE-2016-8610,CVE-2017-5335,CVE-2017-5336,CVE-2017-5337 Sources used: openSUSE Leap 42.2 (src): gnutls-3.2.15-9.1 openSUSE Leap 42.1 (src): gnutls-3.2.15-8.1