Ubuntu Security Notice USN-3183-1

Discussion in 'News Aggregator' started by Packet Storm, 2 Feb 2017.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 3183-1 - Stefan Buehler discovered that GnuTLS incorrectly verified the serial length of OCSP responses. A remote attacker could possibly use this issue to bypass certain certificate validation measures. This issue only applied to Ubuntu 16.04 LTS. Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts. A remote attacker could possibly use this issue to cause GnuTLS to hang, resulting in a denial of service. This issue has only been addressed in Ubuntu 16.04 LTS and Ubuntu 16.10. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...