- Issued:
- 2013-02-20
- Updated:
- 2013-02-20
RHBA-2013:0425 - gnutls bug fix update
Synopsis
gnutls bug fix update
Type/Severity
Bug Fix Advisory (none)
Topic
Updated gnutls packages that fix four bugs are now available for Red Hat Enterprise Linux 6.
Description
The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.
This update fixes the following bugs:
-
Previously, the gnutls_priority_init.3 man page contained incorrect information on the gnutls-2.8.5-safe-renegotiation patch, particularly on special control keywords. The manual page has been updated to provide accurate information about the described subject. (BZ#648297)
-
Prior to this update, the gnutls_x509_privkey_import() function failed to load private keys in the PKCS#8 format. Consequently, these keys were not processed by applications which use gnutls_x509_privkey_import(). This bug has been fixed, and gnutls_x509_privkey_import() now allows loading of private keys formatted in PKCS#8. (BZ#745242)
-
Multiple bugs were present in the implementation of the TLS-1.2 protocol in the gnutls package. Consequently, gnutls was incompatible with clients and servers conforming to the TLS-1.2 protocol standard. With this update, the TLS-1.2 implementation has been fixed. As a result, the compatibility of gnutls with other TLS-1.2 clients and servers is now assured. (BZ#771378)
-
Previously, the gnutls-cli-debug man page contained typographical errors and incorrect information on the command-line options. The manual page has been updated, and no longer contains the aforementioned errors. (BZ#807746)
All users of gnutls are advised to upgrade to these updated packages, which fix these bugs.
Solution
Before applying this update, make sure all previously-released errata relevant to your system have been applied.
This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/knowledge/articles/11258
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat Enterprise Linux for Scientific Computing | 6 | x86_64 |
| Red Hat Enterprise Linux for Power, big endian | 6 | ppc64 |
| Red Hat Enterprise Linux for IBM z Systems | 6 | s390x |
| Red Hat Enterprise Linux Workstation | 6 | x86_64 |
| Red Hat Enterprise Linux Workstation | 6 | i386 |
| Red Hat Enterprise Linux Server | 6 | x86_64 |
| Red Hat Enterprise Linux Server | 6 | i386 |
| Red Hat Enterprise Linux Server from RHUI | 6 | x86_64 |
| Red Hat Enterprise Linux Server from RHUI | 6 | i386 |
| Red Hat Enterprise Linux Server - Retired Extended Life Cycle Support | 6 | x86_64 |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support | 6 | x86_64 |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support | 6 | i386 |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension | 6 | x86_64 |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension | 6 | i386 |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension (for IBM z Systems) | 6 | s390x |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) | 6 | s390x |
| Red Hat Enterprise Linux Desktop | 6 | x86_64 |
| Red Hat Enterprise Linux Desktop | 6 | i386 |
Updated Packages
- gnutls-debuginfo-2.8.5-10.el6.s390.rpm
- gnutls-devel-2.8.5-10.el6.ppc.rpm
- gnutls-2.8.5-10.el6.src.rpm
- gnutls-guile-2.8.5-10.el6.i686.rpm
- gnutls-debuginfo-2.8.5-10.el6.s390x.rpm
- gnutls-guile-2.8.5-10.el6.x86_64.rpm
- gnutls-2.8.5-10.el6.i686.rpm
- gnutls-2.8.5-10.el6.ppc64.rpm
- gnutls-utils-2.8.5-10.el6.i686.rpm
- gnutls-guile-2.8.5-10.el6.ppc64.rpm
- gnutls-debuginfo-2.8.5-10.el6.x86_64.rpm
- gnutls-2.8.5-10.el6.ppc.rpm
- gnutls-2.8.5-10.el6.s390x.rpm
- gnutls-2.8.5-10.el6.x86_64.rpm
- gnutls-utils-2.8.5-10.el6.ppc64.rpm
- gnutls-utils-2.8.5-10.el6.s390x.rpm
- gnutls-2.8.5-10.el6.s390.rpm
- gnutls-devel-2.8.5-10.el6.s390.rpm
- gnutls-guile-2.8.5-10.el6.s390.rpm
- gnutls-devel-2.8.5-10.el6.ppc64.rpm
- gnutls-guile-2.8.5-10.el6.s390x.rpm
- gnutls-devel-2.8.5-10.el6.i686.rpm
- gnutls-debuginfo-2.8.5-10.el6.i686.rpm
- gnutls-debuginfo-2.8.5-10.el6.ppc.rpm
- gnutls-devel-2.8.5-10.el6.x86_64.rpm
- gnutls-devel-2.8.5-10.el6.s390x.rpm
- gnutls-guile-2.8.5-10.el6.ppc.rpm
- gnutls-debuginfo-2.8.5-10.el6.ppc64.rpm
- gnutls-utils-2.8.5-10.el6.x86_64.rpm
Fixes
- This content is not included.BZ - 648297
- This content is not included.BZ - 745242
- This content is not included.BZ - 807746
- This content is not included.BZ - 864817
CVEs
(none)
References
(none)
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.