oss-sec mailing list archives
CVE Request: GnuTLS: OCSP validation issue (GNUTLS-SA-2016-3)
From: Salvatore Bonaccorso <carnil () debian org>
Date: Sun, 18 Sep 2016 14:31:24 +0200
Hi Some days ago new GnuTLS version were released for GNUTLS-SA-2016-3 (OCSP validation issue):
Stefan Bühler discovered an issue that affects validation of certificates using OCSP responses, which can falsely report a certificate as valid under certain circumstances. That issue affects gnutls 3.3.24, 3.4.14, 3.5.3 and previous versions. Write-up[0] by Stefan Bühler Recommendation: Upgrade to GnuTLS versions 3.4.15, 3.5.4 or apply the patch referenced in the mail above.
Upstream fix is at [1]. This is as well tracked in Red Hat's bugzilla at [2]. Could you please assign a CVE for this issue? Regards, Salvatore [0] https://lists.gnupg.org/pipermail/gnutls-devel/2016-September/008146.html [1] https://gitlab.com/gnutls/gnutls/commit/964632f37dfdfb914ebc5e49db4fa29af35b1de9 [2] https://bugzilla.redhat.com/show_bug.cgi?id=1374266
Current thread:
- CVE Request: GnuTLS: OCSP validation issue (GNUTLS-SA-2016-3) Salvatore Bonaccorso (Sep 18)
- Re: CVE Request: GnuTLS: OCSP validation issue (GNUTLS-SA-2016-3) cve-assign (Sep 18)