{"affected":[],"aliases":[],"details":"\nGnuTLS has been patched to ensure proper parsing of session ids during the \nTLS/SSL handshake. Additionally, three issues inherited from libtasn1 have \nbeen fixed.\n\nFurther information is available at \nhttp://www.gnutls.org/security.html#GNUTLS-SA-2014-3\n<http://www.gnutls.org/security.html#GNUTLS-SA-2014-3>\n\nThese security issues have been fixed:\n\n    * Possible memory corruption during connect (CVE-2014-3466)\n    * Multiple boundary check issues could allow DoS (CVE-2014-3467)\n    * asn1_get_bit_der() can return negative bit length (CVE-2014-3468)\n    * Possible DoS by NULL pointer dereference (CVE-2014-3469)\n\nSecurity Issue references:\n\n    * CVE-2014-3466\n      <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3466>\n\n","id":"SUSE-SU-2015:0675-1","modified":"2014-06-03T20:02:07Z","published":"2014-06-03T20:02:07Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20150675-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/821818"},{"type":"REPORT","url":"https://bugzilla.suse.com/835760"},{"type":"REPORT","url":"https://bugzilla.suse.com/865804"},{"type":"REPORT","url":"https://bugzilla.suse.com/865993"},{"type":"REPORT","url":"https://bugzilla.suse.com/880730"},{"type":"REPORT","url":"https://bugzilla.suse.com/880910"},{"type":"REPORT","url":"https://bugzilla.suse.com/919938"},{"type":"REPORT","url":"https://bugzilla.suse.com/921684"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2009-5138"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2013-2116"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-0092"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-3466"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-8155"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0282"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0294"}],"related":["CVE-2009-5138","CVE-2013-2116","CVE-2014-0092","CVE-2014-3466","CVE-2014-8155","CVE-2015-0282","CVE-2015-0294"],"summary":"Security update for gnutls","upstream":["CVE-2009-5138","CVE-2013-2116","CVE-2014-0092","CVE-2014-3466","CVE-2014-8155","CVE-2015-0282","CVE-2015-0294"]}