UbuntuUpdates.org

Package "libgnutlsxx28"

Name: libgnutlsxx28

Description:

GNU TLS library - C++ runtime library

Latest version: 3.2.11-2ubuntu1.1
Release: trusty (14.04)
Level: security
Repository: universe
Head package: gnutls28
Homepage: http://www.gnutls.org/

Links


Download "libgnutlsxx28"


Other versions of "libgnutlsxx28" in Trusty

Repository Area Version
base universe 3.2.11-2ubuntu1
updates universe 3.2.11-2ubuntu1.2

Changelog

Version: 3.2.11-2ubuntu1.1 2015-06-11 19:07:01 UTC

  gnutls28 (3.2.11-2ubuntu1.1) trusty-security; urgency=medium

  [ Gianfranco Costamagna ]
  * SECURITY UPDATE: Denial of service and possible remote arbitrary code
    execution via crafted ServerHello message
    - debian/patches/21_CVE-2014-3466.patch: Add upper bounds check for
      session id size. Based on upstream patch. (LP: #1326779)

  [ Tyler Hicks ]
  * debian/patches/21_CVE-2014-3466.patch: Fold in the test for
    CVE-2014-3466's fix. Based on upstream patch.

 -- Tyler Hicks <email address hidden> Thu, 11 Jun 2015 10:42:35 -0500

1326779 libgnutls28 appears to not have been updated for CVE-2014-3466 in Trusty
CVE-2014-3466 Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allo



About   -   Send Feedback to @ubuntu_updates