SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Application (Security)  >   libtASN1 Vendors:   gnutls.org
(Red Hat Issues Fix) libtASN1 asn1_der_decoding() Response Handling Bugs Let Remote Users Deny Service
SecurityTracker Alert ID:  1026992
SecurityTracker URL:  http://securitytracker.com/id/1026992
CVE Reference:   CVE-2012-1569   (Links to External Site)
Date:  Apr 30 2012
Impact:   Denial of service via network
Fix Available:  Yes  Vendor Confirmed:  Yes  Exploit Included:  Yes  
Version(s): prior to 2.12
Description:   A vulnerability was reported in libtASN1. A remote user can cause denial of service conditions.

A remote user can send specially crafted data so that the asn1_der_decoding() will return invalid data and cause an error in the calling function(s), resulting in a crash of the target service.

Matthew Hall of Mu Dynamics reported this vulnerability.

Impact:   A remote user can cause the target service to crash.
Solution:   Red Hat has issued a fix for Red Hat Enterprise Virtualization.

The Red Hat advisory is available at:

https://rhn.redhat.com/errata/RHSA-2012-0531.html

Vendor URL:  www.gnutls.org/ (Links to External Site)
Cause:   Boundary error
Underlying OS:   Linux (Red Hat Enterprise)

Message History:   This archive entry is a follow-up to the message listed below.
Mar 21 2012 libtASN1 asn1_der_decoding() Response Handling Bugs Let Remote Users Deny Service



 Source Message Contents

Date:  Mon, 30 Apr 2012 18:02:04 +0000
Subject:  [RHSA-2012:0531-01] Important: rhev-hypervisor6 security and bug fix update

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Important: rhev-hypervisor6 security and bug fix update
Advisory ID:       RHSA-2012:0531-01
Product:           Red Hat Enterprise Virtualization
Advisory URL:      https://rhn.redhat.com/errata/RHSA-2012-0531.html
Issue date:        2012-04-30
CVE Names:         CVE-2012-0864 CVE-2012-1569 CVE-2012-1573 
=====================================================================

1. Summary:

An updated rhev-hypervisor6 package that fixes three security issues and
one bug is now available.

The Red Hat Security Response Team has rated this update as having
important security impact. Common Vulnerability Scoring System (CVSS) base
scores, which give detailed severity ratings, are available for each
vulnerability from the CVE links in the References section.

2. Relevant releases/architectures:

RHEV Hypervisor for RHEL-6 - noarch

3. Description:

The rhev-hypervisor6 package provides a Red Hat Enterprise Virtualization
Hypervisor ISO disk image. The Red Hat Enterprise Virtualization Hypervisor
is a dedicated Kernel-based Virtual Machine (KVM) hypervisor. It includes
everything necessary to run and manage virtual machines: A subset of the
Red Hat Enterprise Linux operating environment and the Red Hat Enterprise
Virtualization Agent.

Note: Red Hat Enterprise Virtualization Hypervisor is only available for
the Intel 64 and AMD64 architectures with virtualization extensions.

A flaw was found in the way libtasn1 decoded DER data. An attacker could
create carefully-crafted DER encoded input (such as an X.509 certificate)
that, when parsed by an application that uses libtasn1 (such as
applications using GnuTLS), could cause the application to crash.
(CVE-2012-1569)

A flaw was found in the way GnuTLS decrypted malformed TLS records. This
could cause a TLS/SSL client or server to crash when processing a
specially-crafted TLS record from a remote TLS/SSL connection peer.
(CVE-2012-1573)

An integer overflow flaw was found in the implementation of the printf
functions family. This could allow an attacker to bypass FORTIFY_SOURCE
protections and execute arbitrary code using a format string flaw in an
application, even though these protections are expected to limit the
impact of such flaws to an application abort. (CVE-2012-0864)

Red Hat would like to thank Matthew Hall of Mu Dynamics for reporting
CVE-2012-1569 and CVE-2012-1573.

This updated package provides updated components that include fixes for
various security issues. These issues have no security impact on Red Hat
Enterprise Virtualization Hypervisor itself, however. The security fixes
included in this update address the following CVE numbers:

CVE-2011-4128 (gnutls issue)

CVE-2012-0879, CVE-2012-1090, and CVE-2012-1097 (kernel issues)

CVE-2012-0884 and CVE-2012-1165 (openssl issues)

CVE-2012-0060, CVE-2012-0061, and CVE-2012-0815 (rpm issues)

This update also fixes the following bug:

* The Hypervisor previously set the lro_disable option for the enic driver.
The driver does not support this option, as a result the Hypervisor did
not correctly detect and configure the network interfaces of a Cisco M81KR
adaptor, when present. The Hypervisor has been updated and no longer sets
the invalid option for this driver. (BZ#809463)

Users of Red Hat Enterprise Virtualization Hypervisor are advised to
upgrade to this updated package, which fixes these issues.

4. Solution:

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258

5. Bugs fixed (http://bugzilla.redhat.com/):

794766 - CVE-2012-0864 glibc: FORTIFY_SOURCE format string protection bypass via "nargs" integer overflow
804920 - CVE-2012-1569 libtasn1: DER decoding buffer overflow (GNUTLS-SA-2012-3, MU-201202-02)
805432 - CVE-2012-1573 gnutls: TLS record handling issue (GNUTLS-SA-2012-2, MU-201202-01)

6. Package List:

RHEV Hypervisor for RHEL-6:

noarch:
rhev-hypervisor6-6.2-20120423.1.el6_2.noarch.rpm
rhev-hypervisor6-tools-6.2-20120423.1.el6_2.noarch.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/#package

7. References:

https://www.redhat.com/security/data/cve/CVE-2012-0864.html
https://www.redhat.com/security/data/cve/CVE-2012-1569.html
https://www.redhat.com/security/data/cve/CVE-2012-1573.html
https://access.redhat.com/security/updates/classification/#important

8. Contact:

The Red Hat security contact is <secalert@redhat.com>.  More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2012 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (GNU/Linux)

iD8DBQFPntOAXlSAg2UNWIIRArUzAJ0drm31+JZVcz/mtQfiDwvMmZx7mgCgheAC
8kiDppSITlZg/DVi+lj2pfo=
=RLcA
-----END PGP SIGNATURE-----


--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce
 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2013, SecurityGlobal.net LLC