lp:ubuntu/quantal-security/gnutls26

Created by Ubuntu Package Importer on 2013-02-27 and last modified on 2014-03-03
Get this branch:
bzr branch lp:ubuntu/quantal-security/gnutls26
Members of Ubuntu branches can upload to this branch. Log in for directions.

Branch merges

Related bugs

Related blueprints

Branch information

Owner:
Ubuntu branches
Review team:
Ubuntu Development Team
Status:
Mature

Recent revisions

40. By Marc Deslauriers on 2014-03-03

* SECURITY UPDATE: certificate validation bypass
  - debian/patches/CVE-2014-0092.patch: correct return codes in
    lib/x509/verify.c.
  - CVE-2014-0092

39. By Marc Deslauriers on 2014-02-24

* SECURITY UPDATE: incorrect v1 intermediate cert handling
  - debian/patches/CVE-2014-1959.patch: don't consider a v1 intermediate
    cert to be a valid CA by default in lib/x509/verify.c.
  - CVE-2014-1959

38. By Marc Deslauriers on 2013-05-27

* SECURITY UPDATE: denial of service via incorrect pad
  - debian/patches/CVE-2013-2116.patch: added sanity check in
    lib/gnutls_cipher.c.
  - CVE-2013-2116

37. By Marc Deslauriers on 2013-02-25

* SECURITY UPDATE: "Lucky Thirteen" timing side-channel TLS attack
  - debian/patches/CVE-2013-1619.patch: avoid timing attacks in
    lib/gnutls_cipher.c, lib/gnutls_hash_int.h.
  - CVE-2013-1619

36. By Thorsten Glaser on 2012-05-24

Apply upstream patch to fix validation of certificates when more than
one with the same short hash exists in the CA bundle (LP: #1003841).

35. By Tyler Hicks on 2012-04-11

* SECURITY UPDATE: Denial of service via crafted TLS record (LP: #978661)
  - debian/patches/CVE-2012-1573.patch: Validate the size of a
    GenericBlockCipher structure as it is processed. Based on upstream
    patch.
  - CVE-2012-1573

34. By Colin Watson on 2012-01-24

Bump the version of gnutls-doc too, for the same reason as gnutls-bin.

33. By Colin Watson on 2012-01-24

Start building gnutls-bin from this source package again, superseding
the version in gnutls28: gnutls28's licensing is currently too strict
for many of the free software packages built against it in Ubuntu main
and we only want to support a single version. Bump its version to
achieve this.

32. By Andreas Metzler <email address hidden> on 2011-12-17

Disable gnutls-guile package, let it be provided by gnutls28.

31. By Andreas Metzler <email address hidden> on 2011-12-03

* Prepare for uploading gnutls28 to unstable.
  + Drop gnutls-bin package, it is going to be provided by gnutls28.
  + Binaries are still useful for debugging, ship them with libgnutls-dbg
    in LIBDIR/libgnutls26.

Branch metadata

Branch format:
Branch format 7
Repository format:
Bazaar repository format 2a (needs bzr 1.16 or later)
Stacked on:
lp:ubuntu/raring/gnutls26
This branch contains Public information 
Everyone can see this information.

Subscribers