This update for gnutls fixes the following security issues:
CVE-2015-8313: First byte of the padding in CBC mode is not checked (bsc#957568)
CVE-2015-2806: Two-byte stack overflow in asn1_der_decoding (bsc#924828)
Affected Packages
gnutls
SUSE Linux Enterprise Desktop 11 SP3SUSE Linux Enterprise Desktop 11 SP4SUSE Linux Enterprise High Availability Extension 11 SP3SUSE Linux Enterprise High Availability Extension 11 SP4SUSE Linux Enterprise Server 11 SP3
Fixed in:
2.4.1-24.39.60.1
libgnutls26
SUSE Linux Enterprise Desktop 11 SP3SUSE Linux Enterprise Desktop 11 SP4SUSE Linux Enterprise Server 11 SP3SUSE Linux Enterprise Server 11 SP3-TERADATASUSE Linux Enterprise Server 11 SP4
Fixed in:
2.4.1-24.39.60.1
libgnutls26-32bit
SUSE Linux Enterprise Desktop 11 SP3SUSE Linux Enterprise Desktop 11 SP4SUSE Linux Enterprise Server 11 SP3SUSE Linux Enterprise Server 11 SP3-TERADATASUSE Linux Enterprise Server 11 SP4
Fixed in:
2.4.1-24.39.60.1
libgnutls-extra26
SUSE Linux Enterprise High Availability Extension 11 SP3SUSE Linux Enterprise High Availability Extension 11 SP4SUSE Linux Enterprise Server 11 SP3SUSE Linux Enterprise Server 11 SP3-TERADATASUSE Linux Enterprise Server 11 SP4
Fixed in:
2.4.1-24.39.60.1
libgnutls26-x86
SUSE Linux Enterprise Server 11 SP3SUSE Linux Enterprise Server 11 SP3-TERADATASUSE Linux Enterprise Server 11 SP4SUSE Linux Enterprise Server for SAP Applications 11 SP3SUSE Linux Enterprise Server for SAP Applications 11 SP4
Fixed in:
2.4.1-24.39.60.1
libgnutls-devel
SUSE Linux Enterprise Software Development Kit 11 SP3SUSE Linux Enterprise Software Development Kit 11 SP4
Fixed in:
2.4.1-24.39.60.1
libgnutls-extra-devel
SUSE Linux Enterprise Software Development Kit 11 SP3SUSE Linux Enterprise Software Development Kit 11 SP4