gnutls12 vulnerability

Related Vulnerabilities: CVE-2006-7239  

Under certain circumstances, an attacker might be able to crash GnuTLS.

It was discovered that GnuTLS did not always properly verify the hash algorithm of X.509 certificates. If an application linked against GnuTLS processed a crafted certificate, an attacker could make GnuTLS dereference a NULL pointer and cause a DoS via application crash.

3 June 2010

gnutls12 vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 6.06 LTS

Summary

Under certain circumstances, an attacker might be able to crash GnuTLS.

Software Description

  • gnutls12 - the GNU TLS library

Details

It was discovered that GnuTLS did not always properly verify the hash algorithm of X.509 certificates. If an application linked against GnuTLS processed a crafted certificate, an attacker could make GnuTLS dereference a NULL pointer and cause a DoS via application crash.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 6.06 LTS
libgnutls12 - 1.2.9-2ubuntu1.8

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References