[ubuntu/trusty-security] gnutls26 2.12.23-12ubuntu2.6 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Wed Feb 1 17:43:03 UTC 2017


gnutls26 (2.12.23-12ubuntu2.6) trusty-security; urgency=medium

  * SECURITY UPDATE: out of memory error in stream reading functions
    - debian/patches/CVE-2017-5335.patch: add error checking to
      lib/opencdk/read-packet.c.
    - CVE-2017-5335
  * SECURITY UPDATE: stack overflow in cdk_pk_get_keyid
    - debian/patches/CVE-2017-5336.patch: check return code in
      lib/opencdk/pubkey.c.
    - CVE-2017-5336
  * SECURITY UPDATE: heap read overflow when reading streams
    - debian/patches/CVE-2017-5337.patch: add more precise checks to
      lib/opencdk/read-packet.c.
    - CVE-2017-5337

Date: 2017-01-26 19:17:24.751631+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/gnutls26/2.12.23-12ubuntu2.6
-------------- next part --------------
Sorry, changesfile not available.


More information about the Trusty-changes mailing list