GnuTLS X.509 Certificate Serial Number Decoding Remote Security Vulnerability
BID:38959
Info
GnuTLS X.509 Certificate Serial Number Decoding Remote Security Vulnerability
| Bugtraq ID: | 38959 |
| Class: | Unknown |
| CVE: |
CVE-2010-0731 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 25 2010 12:00AM |
| Updated: | Oct 12 2010 03:09PM |
| Credit: | Reported in a Red Hat advisory |
| Vulnerable: |
S.u.S.E. SUSE Linux Enterprise Server 9 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux AS 4 RedHat Enterprise Linux Desktop version 4 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 GNU GnuTLS 1.2 GNU GnuTLS 1.0.25 GNU GnuTLS 1.0.23 GNU GnuTLS 1.0.20 GNU GnuTLS 1.0.17 GNU GnuTLS 1.0.16 GNU GnuTLS 1.0.15 GNU GnuTLS 1.0.14 GNU GnuTLS 1.0.13 GNU GnuTLS 1.0.9 GNU GnuTLS 1.0.8 GNU GnuTLS 1.0.7 GNU GnuTLS 1.0.6 GNU GnuTLS 1.0.5 GNU GnuTLS 1.0.4 GNU GnuTLS 1.0.3 GNU GnuTLS 1.0.2 GNU GnuTLS 1.0.1 GNU GnuTLS 1.0 Avaya Proactive Contact 4.1.2 Avaya Proactive Contact 4.1.1 Avaya Proactive Contact 4.1 Avaya Proactive Contact 4.0 Avaya Messaging Storage Server 5.1 Avaya Messaging Storage Server 5.0 Avaya Messaging Storage Server 4.0 Avaya Message Networking 5.2 Avaya Message Networking 3.1 Avaya Meeting Exchange 5.0 .0.52 Avaya Meeting Exchange 5.2 SP1 Avaya Meeting Exchange 5.2 Avaya Meeting Exchange 5.1 SP1 Avaya Meeting Exchange 5.1 Avaya Meeting Exchange 5.0 SP2 Avaya Meeting Exchange 5.0 SP1 Avaya Meeting Exchange 5.0 Avaya Intuity AUDIX LX 2.0 SP2 Avaya Intuity AUDIX LX 2.0 SP1 Avaya Intuity AUDIX LX 2.0 Avaya Communication Manager 5.1.2 Avaya Communication Manager 4.0.3 SP1 Avaya Communication Manager 3.1.4 SP2 Avaya Communication Manager 2.0.1 Avaya Communication Manager 2.0 Avaya Communication Manager 1.3.1 Avaya Communication Manager 1.1 Avaya Communication Manager 5.2 Avaya Communication Manager 5.1 Avaya Communication Manager 5.0 SP3 Avaya Communication Manager 5.0 Avaya Communication Manager 4.0 Avaya Communication Manager 3.1 Avaya Communication Manager 3.0 Avaya Communication Manager 2.2 Avaya Communication Manager 2.1 Avaya Aura SIP Enablement Services 5.2.1 Avaya Aura SIP Enablement Services 3.1.1 Avaya Aura SIP Enablement Services 3.1 Avaya Aura SIP Enablement Services 5.2 Avaya Aura SIP Enablement Services 3.1 Avaya Aura Communication Manager 5.2 Avaya Aura Communication Manager 5.1 Avaya Aura Communication Manager 4.0 Avaya Aura Communication Manager 4.0 |
| Not Vulnerable: |
GNU GnuTLS 1.2.1 Avaya Aura Communication Manager 6.0.1 |
Discussion
GnuTLS X.509 Certificate Serial Number Decoding Remote Security Vulnerability
GnuTLS is prone to a remote security vulnerability.
An attacker can exploit this issue to potentially execute arbitrary code, trigger denial-of-service conditions, or bypass certificate revocation list (CRL) checks, causing clients to accept expired or invalid certificates from servers.
GnuTLS is prone to a remote security vulnerability.
An attacker can exploit this issue to potentially execute arbitrary code, trigger denial-of-service conditions, or bypass certificate revocation list (CRL) checks, causing clients to accept expired or invalid certificates from servers.
Exploit / POC
GnuTLS X.509 Certificate Serial Number Decoding Remote Security Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
GnuTLS X.509 Certificate Serial Number Decoding Remote Security Vulnerability
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Corporate Server 4.0
MandrakeSoft Corporate Server 4.0 x86_64
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Corporate Server 4.0
-
Mandriva gnutls-1.0.25-2.6.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libgnutls11-devel-1.0.25-2.6.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libgnutls11-1.0.25-2.6.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0 x86_64
-
Mandriva gnutls-1.0.25-2.6.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64gnutls11-devel-1.0.25-2.6.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64gnutls11-1.0.25-2.6.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/
References
GnuTLS X.509 Certificate Serial Number Decoding Remote Security Vulnerability
References:
References: