[ubuntu/groovy-proposed] gnutls28 3.6.13-4ubuntu5 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Tue Sep 8 15:15:14 UTC 2020


gnutls28 (3.6.13-4ubuntu5) groovy; urgency=medium

  * SECURITY UPDATE: null pointer deref via no_renegotiation alert
    - debian/patches/CVE-2020-24659.patch: reject no_renegotiation alert if
      handshake is incomplete in lib/gnutls_int.h, lib/handshake.c.
    - CVE-2020-24659

Date: Tue, 08 Sep 2020 10:09:39 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/gnutls28/3.6.13-4ubuntu5
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 08 Sep 2020 10:09:39 -0400
Source: gnutls28
Architecture: source
Version: 3.6.13-4ubuntu5
Distribution: groovy
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Changes:
 gnutls28 (3.6.13-4ubuntu5) groovy; urgency=medium
 .
   * SECURITY UPDATE: null pointer deref via no_renegotiation alert
     - debian/patches/CVE-2020-24659.patch: reject no_renegotiation alert if
       handshake is incomplete in lib/gnutls_int.h, lib/handshake.c.
     - CVE-2020-24659
Checksums-Sha1:
 1e5c4226649705e9aa9dab8ddb6336cd3b61c72a 3586 gnutls28_3.6.13-4ubuntu5.dsc
 59d1055630f14d74516850b8d58591e7be5c8788 72368 gnutls28_3.6.13-4ubuntu5.debian.tar.xz
 541254bb8fe5e19b7f9b53a58a76f47b488ca8a2 7186 gnutls28_3.6.13-4ubuntu5_source.buildinfo
Checksums-Sha256:
 b836333eb35d213d8c6a3dcd238173b3520fa732342250a4f2182352c19e0462 3586 gnutls28_3.6.13-4ubuntu5.dsc
 80a2621f4ffe17960522bdacbcc1221087fbe1cc32bc5596fa07c7d5f1529b35 72368 gnutls28_3.6.13-4ubuntu5.debian.tar.xz
 9327bf2be7d752f96566530a99ddd6fdf9dc7856867000d7c36e8ef437201bb5 7186 gnutls28_3.6.13-4ubuntu5_source.buildinfo
Files:
 ef0a32b57138cca0b6d1be2af86967e2 3586 libs optional gnutls28_3.6.13-4ubuntu5.dsc
 c069ce355585829d9b4066090b1be99f 72368 libs optional gnutls28_3.6.13-4ubuntu5.debian.tar.xz
 0e59e4474ef9c272b63e6be088d0ebed 7186 libs optional gnutls28_3.6.13-4ubuntu5_source.buildinfo
Original-Maintainer: Debian GnuTLS Maintainers <pkg-gnutls-maint at lists.alioth.debian.org>

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl9Xn44ACgkQZWnYVadE
vpN4fg//Qto7G8mNcq9F4wtfnPq9w337QCaOCKwLrWVBkSY0s6DMmY34T52wsYxR
T/fqNIM/ojFtmRM6pyZOGxT5uavdjLQktizr1bUOjOl8XhoOyoU1BAz6EVeZmWW+
JbB5Dn1gFjs/GtVjVQQux1wpuASeHqYSYT7P9gu07qLSAIgSN8am1VYVinZfD646
jJ41sNx7mPUuRwxvvgpCvhX4Pr52U3QGjhxDHI4qHTMDb/oZ1Y4Y8iy78lhuzacC
IUjSDx/iYEPvmhGJ7lqoBKq2cL2psKl8jNQ+FKxbgb6708b9GeW53gwovWM/ll7W
8b+rYRqV2Cjc4XWB3vmwR97KzqMTGJb2ou18O3RyUZvSrUUimh7TrE0EEVleFzGq
OJCnlhRc8tZPg2imIyc2qzdRbB5w2fgzpG2CbzV4NDAmK4fBm/+MNdZO8FuaQb/Q
6HV1rotNsIkr2AE5JwMrvPzDCyLDe1CHZ0uIjHY2xWkT9+ZjTS8NL00J1psIwj5z
lRJAMTRAlDosfhQBBHkfcUAkAnabZh1BGuyL3+ggFU/aSuKKqpz2fxWjL8UxvaOh
raszt8hk2k9KathmcR3a2WfGYbUcABuGh2kQH5q453pzRD4IPn3tYn4F+P1jnALY
u3mAyg5Ly20oheWVCFEKtecDRC1a6CHAn82hmx6qkihrMpNaKUs=
=ARam
-----END PGP SIGNATURE-----


More information about the Groovy-changes mailing list