Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2006:166: gnutls Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the gnutls package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2006:166 (gnutls).
verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3,
does not properly handle excess data in the digestAlgorithm.parameters
field when generating a hash, which allows remote attackers to forge a
PKCS #1 v1.5 signature that is signed by that RSA key and prevents
GnuTLS from correctly verifying X.509 and other certificates that use
PKCS, a variant of CVE-2006-4339.
The provided packages have been patched to correct this issues.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:166
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.