SuSE: 2014:0319-1: critical: gnutls
Summary
The GnuTLS library received a critical security fix and
other updates:
* CVE-2014-0092: The X.509 certificate verification had
incorrect error handling, which could lead to broken
certificates marked as being valid.
* CVE-2009-5138: A verification problem in handling V1
certificates could also lead to V1 certificates incorrectly
being handled.
Additionally a memory leak in PSK authentication has been
fixed (bnc#835760).
Security Issue references:
* CVE-2014-0092
References
#835760 #865804 #865993
Cross- CVE-2009-5138 CVE-2014-0092
Affected Products:
SUSE Linux Enterprise Software Development Kit 11 SP3
SUSE Linux Enterprise Server 11 SP3 for VMware
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise High Availability Extension 11 SP3
SUSE Linux Enterprise Desktop 11 SP3
https://www.suse.com/security/cve/CVE-2009-5138.html
https://www.suse.com/security/cve/CVE-2014-0092.html
https://bugzilla.novell.com/835760
https://bugzilla.novell.com/865804
https://bugzilla.novell.com/865993
https://login.microfocus.com/nidp/app/login