shield
Security update for gnutls
SUSE-SLE-SAP-12-SP2-2018-1977
This update for gnutls fixes the following issues: This update for gnutls fixes the following issues: Security issues fixed: - Improved mitigations against Lucky 13 class of attacks - "Just in Time" PRIME + PROBE cache-based side channel attack can lead to plaintext recovery (CVE-2018-10846, bsc#1105460) - HMAC-SHA-384 vulnerable to Lucky thirteen attack due to use of wrong constant (CVE-2018-10845, bsc#1105459) - HMAC-SHA-256 vulnerable to Lucky thirteen attack due to not enough dummy function calls (CVE-2018-10844, bsc#1105437) - The _asn1_check_identifier function in Libtasn1 caused a NULL pointer dereference and crash (CVE-2017-10790, bsc#1047002)
-
Release DateSep 24 2018
-
ReferencesBugzilla: 1105437, 1105460, 1105459, 1047002
CVEs: CVE-2018-10845, CVE-2018-10844, CVE-2017-10790, CVE-2018-10846 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Linux Enterprise Server for SAP Applications 12.2 ppc64le
-
Packagesgnutls
The GNU Transport Layer Security Librarylibgnutls-openssl273.2.15-18.6.1 lock rpm lock src
The GNU Transport Layer Security Librarylibgnutls283.2.15-18.6.1 lock rpm
The GNU Transport Layer Security Library3.2.15-18.6.1 lock rpm
SUSE Linux Enterprise Server for SAP Applications 12.2 x86_64
-
Packagesgnutls
The GNU Transport Layer Security Librarylibgnutls-openssl273.2.15-18.6.1 lock rpm lock src
The GNU Transport Layer Security Librarylibgnutls283.2.15-18.6.1 lock rpm
The GNU Transport Layer Security Librarylibgnutls28-32bit3.2.15-18.6.1 lock rpm
The GNU Transport Layer Security Library3.2.15-18.6.1 lock rpm