Branches for Jaunty

Name Status Last Modified Last Commit
lp://staging/ubuntu/jaunty-security/gnutls26 bug 2 Mature 2009-08-20 18:27:23 UTC
13. * SECURITY UPDATE: fix improper handl...

Author: Jamie Strandboge
Revision Date: 2009-08-14 14:01:09 UTC

* SECURITY UPDATE: fix improper handling of '\0' in Common Name (CN) and
  Subject Alternative Name (SAN) in X.509 certificates (LP: #413136)
  - debian/patches/26_CVE-2009-2730.diff: verify length of CN and SAN
    are what we expect and error out if either contains an embedded \0
  - CVE-2009-2730

lp://staging/ubuntu/jaunty-updates/gnutls26 2 Mature 2009-08-20 18:25:25 UTC
13. * SECURITY UPDATE: fix improper handl...

Author: Jamie Strandboge
Revision Date: 2009-08-14 14:01:09 UTC

* SECURITY UPDATE: fix improper handling of '\0' in Common Name (CN) and
  Subject Alternative Name (SAN) in X.509 certificates (LP: #413136)
  - debian/patches/26_CVE-2009-2730.diff: verify length of CN and SAN
    are what we expect and error out if either contains an embedded \0
  - CVE-2009-2730

lp://staging/ubuntu/jaunty/gnutls26 1 Development 2009-06-27 03:21:41 UTC
12. * New patches, syncing with 2.4.3 ups...

Author: Andreas Metzler
Revision Date: 2009-02-07 12:58:51 UTC

* New patches, syncing with 2.4.3 upstream oldstable release:
  + 24_intermedcertificate.patch If a non-root certificate ist trusted
    gnutls certificateificate verification stops there instead of checking
    up to the root of the certificate chain.
  + 22_whitespace.patch - Whitespace only changes, to make it possible to
    apply upstream fixes without manual changes.
  + 25_bufferoverrun.patch. Fix buffer overrun bug in
    gnutls_x509_crt_list_import.
    http://news.gmane.org/find-root.php?message_id=%3c000001c91d6e%2463059c90%242910d5b0%24%40com%3e

13 of 3 results