[ubuntu/trusty-security] gnutls26 2.12.23-12ubuntu2.4 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Fri Jan 8 12:37:41 UTC 2016


gnutls26 (2.12.23-12ubuntu2.4) trusty-security; urgency=medium

  * SECURITY UPDATE: incorrect RSA+MD5 support with TLS 1.2
    - debian/patches/CVE-2015-7575.patch: do not consider any values from
      the extension data to decide acceptable algorithms in
      lib/ext_signature.c.
    - CVE-2015-7575

Date: 2016-01-07 16:39:17.209783+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/gnutls26/2.12.23-12ubuntu2.4
-------------- next part --------------
Sorry, changesfile not available.


More information about the Trusty-changes mailing list