[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2020:1584-1 -- SLES gnutls, libgnutls

ID: oval:org.secpod.oval:def:89003006Date: (C)2021-02-25   (M)2023-03-08
Class: PATCHFamily: unix




This update for gnutls fixes the following issues: - CVE-2020-13777: Fixed an insecure session ticket key construction which could have made the TLS server to not bind the session ticket encryption key with a value supplied by the application until the initial key rotation, allowing an attacker to bypass authentication in TLS 1.3 and recover previous conversations in TLS 1.2 . - Fixed an improper handling of certificate chain with cross-signed intermediate CA certificates .

Platform:
SUSE Linux Enterprise Server 15
Product:
gnutls
libgnutls
Reference:
SUSE-SU-2020:1584-1
CVE-2020-13777
CVE    1
CVE-2020-13777
CPE    3
cpe:/a:gnu:libgnutls
cpe:/o:suse:suse_linux_enterprise_server:15
cpe:/a:gnu:gnutls

© SecPod Technologies