• [SECURITY] [DSA 2697-1] gnutls26 security update

    From Florian Weimer@1:229/2 to All on Wed May 29 22:10:02 2013
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-2697-1 [email protected] http://www.debian.org/security/ Florian Weimer
    May 29, 2013 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : gnutls26
    Vulnerability : out-of-bounds array read
    Problem type : remote
    Debian-specific: no
    CVE ID : CVE-2013-2116
    Debian Bug : 709301

    It was discovered that a malicious client could crash a GNUTLS server
    and vice versa, by sending TLS records encrypted with a block cipher
    which contain invalid padding.

    The oldstable distribution (squeeze) is not affected because the
    security fix that introduced this vulnerability was not applied to it.

    For the stable distribution (wheezy), this problem has been fixed in
    version 2.12.20-7.

    For the unstable distribution (sid), this problem has been fixed in
    version 2.12.23-5.

    We recommend that you upgrade your gnutls26 packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: http://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.10 (GNU/Linux)

    iQEcBAEBAgAGBQJRplgnAAoJEL97/wQC1SS+vdkH/jAIIOkjyJlPm5mxUCH6uDJA mDQ5Vd+0VoSDPz6fPfxWHPbDaFCdPZWU5v7rGlVsIwKXgDRIOuJm30xcKsguVWMz PSgGQIrhVU+79283ZaSO/qXBkaRZ/0Ti9NpBKzguSZWK/PmwwfkMvkvuABF/xgAQ yy5k02XL9pDwM0SX83GGRiJK37qodMAx7kk4PcWT2eO1dlTkiAhLLFS6TDvEAjll bCMoNHqu9wAtOGKKdzOI7RCePy/WR+JQTMTvFLmJ3PlhtRHC7LP6va0AmtPcF+Wl KJSEBZCyQF8BdBobMkUqFI3hXHZ/uT3435A/5nd75vriTnianrhfRxxr9FgS0Nk=
    =3G6P
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)