DSA-2441-1 gnutls26 -- missing bounds check

Related Vulnerabilities: CVE-2012-1573  

Matthew Hall discovered that GNUTLS does not properly handle truncated GenericBlockCipher structures nested inside TLS records, leading to crashes in applications using the GNUTLS library. For the stable distribution (squeeze), this problem has been fixed in version 2.8.6-1+squeeze2. For the unstable distribution (sid), this problem has been fixed in version 2.12.18-1 of the gnutls26 package and version 3.0.17-2 of the gnutls28 package. We recommend that you upgrade your gnutls26 packages.

Debian Security Advisory

DSA-2441-1 gnutls26 -- missing bounds check

Date Reported:
25 Mar 2012
Affected Packages:
gnutls26
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2012-1573.
More information:

Matthew Hall discovered that GNUTLS does not properly handle truncated GenericBlockCipher structures nested inside TLS records, leading to crashes in applications using the GNUTLS library.

For the stable distribution (squeeze), this problem has been fixed in version 2.8.6-1+squeeze2.

For the unstable distribution (sid), this problem has been fixed in version 2.12.18-1 of the gnutls26 package and version 3.0.17-2 of the gnutls28 package.

We recommend that you upgrade your gnutls26 packages.