UbuntuUpdates.org

Package "gnutls28"

Name: gnutls28

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • GNU TLS library - documentation and examples
  • GNU TLS library - DANE security support
  • GNU TLS library - OpenSSL wrapper
  • GNU TLS library - development files

Latest version: 3.8.1-4ubuntu1.2
Release: mantic (23.10)
Level: security
Repository: main

Links



Other versions of "gnutls28" in Mantic

Repository Area Version
base main 3.8.1-4ubuntu1
base universe 3.8.1-4ubuntu1
security universe 3.8.1-4ubuntu1.2
updates main 3.8.1-4ubuntu1.2
updates universe 3.8.1-4ubuntu1.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.8.1-4ubuntu1.2 2024-01-22 15:07:11 UTC

  gnutls28 (3.8.1-4ubuntu1.2) mantic-security; urgency=medium

  * SECURITY UPDATE: timing side-channel attack in the RSA-PSK key exchange
    - debian/patches/CVE-2024-0553.patch: minimize branching after
      decryption in lib/auth/rsa_psk.c.
    - CVE-2024-0553
  * SECURITY UPDATE: DoS via certificate chain with distributed trust
    - debian/patches/CVE-2024-0567.patch: detect loop in certificate chain
      in lib/x509/common.c, tests/test-chains.h.
    - CVE-2024-0567

 -- Marc Deslauriers <email address hidden> Thu, 18 Jan 2024 11:12:38 -0500

Source diff to previous version
CVE-2024-0553 A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertex
CVE-2024-0567 A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when v

Version: 3.8.1-4ubuntu1.1 2023-11-21 16:09:12 UTC

  gnutls28 (3.8.1-4ubuntu1.1) mantic-security; urgency=medium

  * SECURITY UPDATE: timing side-channel inside RSA-PSK key exchange
    - debian/patches/CVE-2023-5981.patch: side-step potential side-channel
      in lib/auth/rsa.c, lib/auth/rsa_psk.c, lib/gnutls_int.h,
      lib/priority.c.
    - CVE-2023-5981

 -- Marc Deslauriers <email address hidden> Fri, 17 Nov 2023 09:08:46 -0500

CVE-2023-5981 ttiming side-channel inside RSA-PSK key exchange



About   -   Send Feedback to @ubuntu_updates