Bug 1287572 (CVE-2015-8313)
Summary: | CVE-2015-8313 gnutls: First byte of the padding in CBC mode is not checked | ||||||
---|---|---|---|---|---|---|---|
Product: | [Other] Security Response | Reporter: | Adam Mariš <amaris> | ||||
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||
Status: | CLOSED NOTABUG | QA Contact: | |||||
Severity: | low | Docs Contact: | |||||
Priority: | low | ||||||
Version: | unspecified | CC: | nmavrogi, tmraz | ||||
Target Milestone: | --- | Keywords: | Security | ||||
Target Release: | --- | ||||||
Hardware: | All | ||||||
OS: | Linux | ||||||
Whiteboard: | |||||||
Fixed In Version: | Doc Type: | Bug Fix | |||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2015-12-02 12:56:26 UTC | Type: | --- | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Bug Depends On: | |||||||
Bug Blocks: | 1287573 | ||||||
Attachments: |
|
Description
Adam Mariš
2015-12-02 11:23:09 UTC
This bug does not affect RHEL-6 or RHEL-7. They have been patched with the proper fixes for Lucky13 which included the fix for that issue. It doesn't affect RHEL-5 either. Details of this issue can be found in the Hanno Böck's blog post: https://blog.hboeck.de/archives/877-A-little-POODLE-left-in-GnuTLS-old-versions.html Here is also the original Ubuntu bug report: https://bugs.launchpad.net/ubuntu/+source/gnutls26/+bug/1510163 Created attachment 1101466 [details]
Patch extracted from Debian packages gnutls26-2.12.20-8+deb7u4
The GnuTLS version of Lucky13 got CVE-2013-1619 (bug 908238) and got corrected in Red Hat Enterprise Linux 5 and 6. As noted above, the fix used addressed Lucky13 without leaving this small problem in. |