Navigation
Package name gnutls
Date September 19th, 2006
Advisory ID MDKSA-2006:166
Affected versions 2006.0, CS4.0

Problem Description

verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3,
does not properly handle excess data in the digestAlgorithm.parameters
field when generating a hash, which allows remote attackers to forge a
PKCS #1 v1.5 signature that is signed by that RSA key and prevents
GnuTLS from correctly verifying X.509 and other certificates that use
PKCS, a variant of CVE-2006-4339.

The provided packages have been patched to correct this issues.

Updated Packages

Mandriva Linux 2006

 7cb7aa3309af51dc44ca8bc9f855bb9b  2006.0/i586/gnutls-1.0.25-2.2.20060mdk.i586.rpm
 e30b5de1b0500830cfbcfbb7a845967d  2006.0/i586/libgnutls11-1.0.25-2.2.20060mdk.i586.rpm
 ddbe8a9d665b50a4614fee5251a8dc39  2006.0/i586/libgnutls11-devel-1.0.25-2.2.20060mdk.i586.rpm 
 aea1556e219f37a6f4be8dadce721830  2006.0/SRPMS/gnutls-1.0.25-2.2.20060mdk.src.rpm

Mandriva Linux 2006/X86_64

 bd9f806eb2319b5d258d142154011650  2006.0/x86_64/gnutls-1.0.25-2.2.20060mdk.x86_64.rpm
 b8046dacc5e4fd5cd11acd7139fba8d9  2006.0/x86_64/lib64gnutls11-1.0.25-2.2.20060mdk.x86_64.rpm
 f26c571f9379dcae4efe5ccb5ddd1bce  2006.0/x86_64/lib64gnutls11-devel-1.0.25-2.2.20060mdk.x86_64.rpm
 e30b5de1b0500830cfbcfbb7a845967d  2006.0/x86_64/libgnutls11-1.0.25-2.2.20060mdk.i586.rpm
 ddbe8a9d665b50a4614fee5251a8dc39  2006.0/x86_64/libgnutls11-devel-1.0.25-2.2.20060mdk.i586.rpm 
 aea1556e219f37a6f4be8dadce721830  2006.0/SRPMS/gnutls-1.0.25-2.2.20060mdk.src.rpm

Corporate Server 4.0

 a2254e8a31891b8bcc609f3cf13c62bb  corporate/4.0/i586/gnutls-1.0.25-2.2.20060mlcs4.i586.rpm
 41b00f4035f895b1e7b51522d1b31342  corporate/4.0/i586/libgnutls11-1.0.25-2.2.20060mlcs4.i586.rpm
 2e74d9730bb73ec4cd4ccd584bd184b9  corporate/4.0/i586/libgnutls11-devel-1.0.25-2.2.20060mlcs4.i586.rpm 
 1e1ff2a8e7eabe7d152c98076f564476  corporate/4.0/SRPMS/gnutls-1.0.25-2.2.20060mlcs4.src.rpm

Corporate Server 4.0/X86_64

 05843e5fd72d31c80c5d8218cf18d812  corporate/4.0/x86_64/gnutls-1.0.25-2.2.20060mlcs4.x86_64.rpm
 112708823292a1f1ca17fa68daac8373  corporate/4.0/x86_64/lib64gnutls11-1.0.25-2.2.20060mlcs4.x86_64.rpm
 a0eaae0c87a0a56ef69a11c8db598fb8  corporate/4.0/x86_64/lib64gnutls11-devel-1.0.25-2.2.20060mlcs4.x86_64.rpm
 41b00f4035f895b1e7b51522d1b31342  corporate/4.0/x86_64/libgnutls11-1.0.25-2.2.20060mlcs4.i586.rpm
 2e74d9730bb73ec4cd4ccd584bd184b9  corporate/4.0/x86_64/libgnutls11-devel-1.0.25-2.2.20060mlcs4.i586.rpm 
 1e1ff2a8e7eabe7d152c98076f564476  corporate/4.0/SRPMS/gnutls-1.0.25-2.2.20060mlcs4.src.rpm

References

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4790

Upgrade

To upgrade automatically, use MandrivaUpdate.


Verification

Please verify the update prior to upgrading to ensure the integrity of the downloaded package. You can do this with the command :

		rpm --checksig package.rpm
		

You can get the GPG public key of the Mandriva Security Team to verify the GPG signature of each RPM.

If you use MandrivaUpdate, the verification of md5 checksum and GPG signature is performed automatically for you.