UbuntuUpdates.org

Package "glib-networking-services"

Name: glib-networking-services

Description:

network-related giomodules for GLib - D-Bus services

Latest version: 2.48.2-1~ubuntu16.04.2
Release: xenial (16.04)
Level: updates
Repository: main
Head package: glib-networking

Links


Download "glib-networking-services"


Other versions of "glib-networking-services" in Xenial

Repository Area Version
base main 2.48.0-1
security main 2.48.2-1~ubuntu16.04.2

Changelog

Version: 2.48.2-1~ubuntu16.04.2 2020-06-29 04:06:21 UTC

  glib-networking (2.48.2-1~ubuntu16.04.2) xenial-security; urgency=medium

  * SECURITY UPDATE: Failure to validate TLS certificate hostname in
    certain conditions, contrary to documented behaviour
    - debian/patches/CVE-2020-13645.patch: Fail certificate verification
      when the server identity is missing. Based on upstream patch.
    - debian/patches/update-test-certs-for-gnutls.patch: Update the
      certificates used for unit test. Taken from upstream.
    - debian/patches/allow-insecure-md2-cert-in-test.patch: Allow insecure
      md2 certificate to used for one unit test. Taken from upstream.
    - CVE-2020-13645

 -- Alex Murray <email address hidden> Tue, 23 Jun 2020 16:38:37 +0930

Source diff to previous version
CVE-2020-13645 In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if th

Version: 2.48.2-1~ubuntu16.04.1 2016-06-07 00:06:29 UTC

  glib-networking (2.48.2-1~ubuntu16.04.1) xenial; urgency=medium

  * Backport from yakkety/unstable to 16.04 (LP: #1581480), with one change
    - Keep the static -dbg package.

1581480 [SRU] New stable release 2.48.2



About   -   Send Feedback to @ubuntu_updates