Fedora alert FEDORA-2014-6891 (gnutls)
| From: | updates@fedoraproject.org | |
| To: | package-announce@lists.fedoraproject.org | |
| Subject: | [SECURITY] Fedora 20 Update: gnutls-3.1.25-1.fc20 | |
| Date: | Wed, 04 Jun 2014 07:53:52 +0000 | |
| Message-ID: | <20140604075352.69B4D218A2@bastion01.phx2.fedoraproject.org> |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2014-6891 2014-05-30 22:50:09 -------------------------------------------------------------------------------- Name : gnutls Product : Fedora 20 Version : 3.1.25 Release : 1.fc20 URL : http://www.gnutls.org/ Summary : A TLS protocol implementation Description : GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, OpenPGP and other required structures. -------------------------------------------------------------------------------- Update Information: Added fix for CVE-2014-3466 -------------------------------------------------------------------------------- ChangeLog: * Fri May 30 2014 Nikos Mavrogiannopoulos <nmav@redhat.com> - 3.1.25-1 - new upstream release (#1103046) * Wed May 14 2014 Nikos Mavrogiannopoulos <nmav@redhat.com> - 3.1.24-1 - new upstream release * Tue Apr 8 2014 Nikos Mavrogiannopoulos <nmav@redhat.com> - 3.1.23-1 - fixes liberal wildcard expansion (#1085264) - fixes certtool generation of encrypted keys even without password (#1085272) * Thu Feb 27 2014 Nikos Mavrogiannopoulos <nmav@redhat.com> - 3.1.20-4 - fixes CVE-2014-0092 (#1071795) * Fri Feb 14 2014 Nikos Mavrogiannopoulos <nmav@redhat.com> 3.1.20-3 - Fix CVE-2014-1959 (#1065094) * Mon Feb 3 2014 Nikos Mavrogiannopoulos <nmav@redhat.com> 3.1.20-1 - new upstream release - Fixed issue with gnutls.info not being available - Compile with trousers - Pulled fix from upstream for illegal supported-ecc extension (#1060411) * Thu Jan 2 2014 Nikos Mavrogiannopoulos <nmav@redhat.com> 3.1.18-3 - Applied complete patch from (#1046672) * Thu Jan 2 2014 Nikos Mavrogiannopoulos <nmav@redhat.com> 3.1.18-2 - Applied fix in suiteb patch to prevent crash in multiple deinitializations (#1046672) * Mon Dec 23 2013 Nikos Mavrogiannopoulos <nmav@redhat.com> 3.1.18-1 - new upstream release * Thu Dec 5 2013 Nikos Mavrogiannopoulos <nmav@redhat.com> 3.1.17-3 - Use the correct root key for unbound (#1012494) - Pull asm fixes from upstream (#973210) - tpmtool manpage is no longer installed (#1036363) * Tue Nov 26 2013 Nikos Mavrogiannopoulos <nmav@redhat.com> 3.1.17-2 - Avoid linking with trousers to prevent introducing new features in f20 * Tue Nov 26 2013 Nikos Mavrogiannopoulos <nmav@redhat.com> 3.1.17-1 - new upstream release - links against the system libopts - links against trousers -------------------------------------------------------------------------------- References: [ 1 ] Bug #1101932 - CVE-2014-3466 gnutls: insufficient session id length check in _gnutls_read_server_hello (GNUTLS-SA-2014-3) https://bugzilla.redhat.com/show_bug.cgi?id=1101932 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update gnutls' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...
