UbuntuUpdates.org

Package "gnutls26"

Name: gnutls26

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • GNU TLS library - commandline utilities
  • GNU TLS library - documentation and examples
  • GNU TLS library - development files
  • GNU TLS library - OpenSSL wrapper

Latest version: 2.12.14-5ubuntu3.14
Release: precise (12.04)
Level: security
Repository: main

Links



Other versions of "gnutls26" in Precise

Repository Area Version
base main 2.12.14-5ubuntu3
updates main 2.12.14-5ubuntu3.14

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2.12.14-5ubuntu3.14 2017-03-20 18:06:48 UTC

  gnutls26 (2.12.14-5ubuntu3.14) precise-security; urgency=medium

  * SECURITY UPDATE: denial of service via warning alerts
    - debian/patches/CVE-2016-8610.patch: set a maximum number of warning
      messages in lib/gnutls_int.h, lib/gnutls_handshake.c,
      lib/gnutls_state.c.
    - CVE-2016-8610

 -- Marc Deslauriers <email address hidden> Wed, 15 Mar 2017 18:59:53 -0400

Source diff to previous version
CVE-2016-8610 SSL/TLS SSL3_AL_WARNING undefined alert DoS

Version: 2.12.14-5ubuntu3.13 2017-02-01 18:06:40 UTC

  gnutls26 (2.12.14-5ubuntu3.13) precise-security; urgency=medium

  * SECURITY UPDATE: out of memory error in stream reading functions
    - debian/patches/CVE-2017-5335.patch: add error checking to
      lib/opencdk/read-packet.c.
    - CVE-2017-5335
  * SECURITY UPDATE: stack overflow in cdk_pk_get_keyid
    - debian/patches/CVE-2017-5336.patch: check return code in
      lib/opencdk/pubkey.c.
    - CVE-2017-5336
  * SECURITY UPDATE: heap read overflow when reading streams
    - debian/patches/CVE-2017-5337.patch: add more precise checks to
      lib/opencdk/read-packet.c.
    - CVE-2017-5337

 -- Marc Deslauriers <email address hidden> Thu, 26 Jan 2017 13:45:02 -0500

Source diff to previous version

Version: 2.12.14-5ubuntu3.12 2016-02-24 18:06:42 UTC

  gnutls26 (2.12.14-5ubuntu3.12) precise-security; urgency=medium

  * debian/patches/compare_ca_name_and_key.patch: when comparing a CA
    certificate with the trusted list compare the name and key. This will
    allow the future removal of 1024-bit RSA keys from the ca-certificates
    package.

 -- Marc Deslauriers <email address hidden> Fri, 05 Feb 2016 13:51:23 -0500

Source diff to previous version

Version: 2.12.14-5ubuntu3.11 2016-01-08 14:06:22 UTC

  gnutls26 (2.12.14-5ubuntu3.11) precise-security; urgency=medium

  * SECURITY UPDATE: incorrect RSA+MD5 support with TLS 1.2
    - debian/patches/CVE-2015-7575.patch: do not consider any values from
      the extension data to decide acceptable algorithms in
      lib/ext_signature.c.
    - CVE-2015-7575

 -- Marc Deslauriers Thu, 07 Jan 2016 10:41:27 -0500

Source diff to previous version
CVE-2015-7575 MD5 signatures accepted within TLS 1.2 ServerKeyExchange in server signature

Version: 2.12.14-5ubuntu3.10 2015-11-30 21:06:23 UTC

  gnutls26 (2.12.14-5ubuntu3.10) precise-security; urgency=low

  * SECURITY UPDATE: Poodle TLS issue
    - debian/patches/fix_tls_poodle.patch: fixes off by one
      issue in padding check.
      Patch created by Hanno Boeck (https://hboeck.de/)
    (LP: #1510163)

 -- Bryan Quigley Wed, 25 Nov 2015 21:37:58 +0000

1510163 Poodle TLS1.0 issue in Trusty (and Precise)



About   -   Send Feedback to @ubuntu_updates