lp://staging/ubuntu/lucid-updates/gnutls26
- Get this branch:
- bzr branch lp://staging/ubuntu/lucid-updates/gnutls26
Branch merges
Branch information
Recent revisions
- 27. By Marc Deslauriers
-
* SECURITY UPDATE: signature forgery issue
- debian/patches/ CVE-2015- 0282.patch: make sure the signature
algorithms match in lib/gnutls_algorithms. c, lib/gnutls_ algorithms. h,
lib/x509/privkey. c, lib/x509/verify.c, lib/x509/x509.c,
lib/x509/x509_ int.h.
- CVE-2015-0282
* SECURITY UPDATE: certificate algorithm consistency issue
- debian/patches/ CVE-2015- 0294.patch: make sure the two signature
algorithms match on cert import in lib/x509/x509.c.
- CVE-2015-0294
* SECURITY UPDATE: missing date/time checks on CA certificates
- debian/patches/ CVE-2014- 8155.patch: perform time verification on
trusted certificate list in lib/includes/gnutls/ x509.h,
lib/x509/verify. c.
- CVE-2014-8155 - 26. By Marc Deslauriers
-
* SECURITY UPDATE: memory corruption due to server hello parsing
- debian/patches/ CVE-2014- 3466.patch: validate session_id_len in
lib/gnutls_ handshake. c.
- CVE-2014-3466 - 25. By Marc Deslauriers
-
* SECURITY UPDATE: certificate validation bypass
- debian/patches/ CVE-2014- 0092.patch: correct return codes in
lib/x509/verify. c.
- CVE-2014-0092 - 24. By Marc Deslauriers
-
* SECURITY UPDATE: denial of service via incorrect pad
- debian/patches/ CVE-2013- 2116.patch: added sanity check in
lib/gnutls_ cipher. c.
- CVE-2013-2116 - 23. By Marc Deslauriers
-
* SECURITY UPDATE: "Lucky Thirteen" timing side-channel TLS attack
- debian/patches/ CVE-2013- 1619.patch: avoid timing attacks in
lib/gnutls_ cipher. c, lib/gnutls_ hash_int. h.
- CVE-2013-1619 - 22. By Thorsten Glaser
-
Apply upstream patch to fix validation of certificates when more than
one with the same short hash exists in the CA bundle (LP: #1003841). - 21. By Tyler Hicks
-
* SECURITY UPDATE: Denial of service in client application
- debian/patches/ CVE-2011- 4128.patch: Fix buffer bounds check when copying
session data. Based on upstream patch.
- CVE-2011-4128
* SECURITY UPDATE: Denial of service via crafted TLS record
- debian/patches/ CVE-2012- 1573.patch: Validate the size of a
GenericBlockCipher structure as it is processed. Based on upstream
patch.
- CVE-2012-1573 - 20. By Andreas Metzler <email address hidden>
-
Add a huge bunch of lintian overrides for the guile stuff to make dak
happy. - 19. By Andreas Metzler <email address hidden>
-
[20_fixtimebomb
.diff] Fix testsuite error. Closes: #552920 - 18. By Andreas Metzler <email address hidden>
-
* New upstream version.
+ Drop debian/patches/ 15_openpgp. diff.
* Sync priorities with override file, libgnutls26 has been bumped from
important to standard.
Branch metadata
- Branch format:
- Branch format 7
- Repository format:
- Bazaar repository format 2a (needs bzr 1.16 or later)
- Stacked on:
- lp://staging/ubuntu/precise/gnutls26