[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 180-1] gnutls26 security update



Package        : gnutls26
Version        : 2.8.6-1+squeeze5
CVE ID         : CVE-2014-8155 CVE-2015-0282 CVE-2015-0294

Multiple vulnerabilities have been discovered in GnuTLS, a library
implementing the TLS and SSL protocols. The Common Vulnerabilities and
Exposures project identifies the following problems:

CVE-2014-8155

    Missing date/time checks on CA certificates

CVE-2015-0282

    GnuTLS does not verify the RSA PKCS #1 signature algorithm to match
    the signature algorithm in the certificate, leading to a potential
    downgrade to a disallowed algorithm without detecting it.

CVE-2015-0294

    GnuTLS does not check whether the two signature algorithms match on
    certificate import.

-- 
Raphaël Hertzog ◈ Debian Developer

Support Debian LTS: http://www.freexian.com/services/debian-lts.html
Learn to master Debian: http://debian-handbook.info/get/

Attachment: signature.asc
Description: Digital signature


Reply to: