Bug 1353843 (GNUTLS-SA-2016-2)

Summary: gnutls: Certificate verification issue when used with the p11-kit trust module
Product: [Other] Security Response Reporter: Andrej Nemec <anemec>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED CURRENTRELEASE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: alonbl, bmcclain, carnil, cfergeau, dblechte, erik-fedora, lsurette, mgoldboi, michal.skrivanek, mike, nmavrogi, rh-spice-bugs, rjones, sardella, srevivo, tmraz, ykaul, ylavi
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: gnutls 3.3.24, gnutls 3.4.14 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-09-13 06:44:40 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On: 1353845, 1353846, 1353847    
Bug Blocks:    

Description Andrej Nemec 2016-07-08 08:06:49 UTC
A vulnerability was discovered in gnutls that affects certificate verification when GnuTLS is used in combination with the p11-kit trust module. This issue affects gnutls 3.3.23, 3.4.12 and later versions.

External References:

http://gnutls.org/security.html#GNUTLS-SA-2016-2

Comment 1 Andrej Nemec 2016-07-08 08:07:07 UTC
Acknowledgments:

Name: Nikos Mavrogiannopoulos (Red Hat)

Comment 2 Andrej Nemec 2016-07-08 08:09:53 UTC
Created mingw-gnutls tracking bugs for this issue:

Affects: fedora-24 [bug 1353847]

Comment 3 Andrej Nemec 2016-07-08 08:10:05 UTC
Created gnutls tracking bugs for this issue:

Affects: fedora-23 [bug 1353845]
Affects: fedora-24 [bug 1353846]

Comment 4 Fedora Update System 2016-07-12 15:05:21 UTC
gnutls-3.4.14-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.

Comment 5 Fedora Update System 2016-07-14 00:22:36 UTC
gnutls-3.4.14-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2016-07-22 18:23:40 UTC
mingw-gnutls-3.4.14-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.