Univention Bugzilla – Bug 51709
gnutls28: Multiple issues (4.4)
Last modified: 2020-07-29 16:50:42 CEST
New Debian gnutls28 3.5.8-5+deb9u5 fixes: This update addresses the following issue: * use-after-free/double-free in certificate verification (CVE-2019-3829)
--- mirror/ftp/4.3/unmaintained/4.3-3/source/gnutls28_3.5.8-5+deb9u4.dsc +++ apt/ucs_4.4-0-errata4.4-5/source/gnutls28_3.5.8-5+deb9u5.dsc @@ -1,3 +1,16 @@ +3.5.8-5+deb9u5 [Fri, 26 Jun 2020 07:31:44 +0200] Andreas Metzler <ametzler@debian.org>: + + * Pull fixes for CVE-2019-3829 / [GNUTLS-SA-2019-03-27, #694]. + + 40_casts_related_to_fix_CVE-2019-3829.patch + + 40_rel3.6.7_01-Automatically-NULLify-after-gnutls_free.patch + + 40_rel3.6.7_01-fuzz-added-fuzzer-for-certificate-verification.patch + + 41_use_datefudge_to_trigger_CVE-2019-3829_testcase.diff + * More important fixes: + + 43_rel3.6.14_10-session_pack-fix-leak-in-error-path.patch + + 44_rel3.6.14_10-Update-session_ticket.c-to-add-support-for-zero-leng.patch + Handle zero length session tickets, fixing connection errors on TLS1.2 + sessions to some big hosting providers. (See LP 1876286) + 3.5.8-5+deb9u4 [Sat, 06 Oct 2018 14:06:18 +0200] Andreas Metzler <ametzler@debian.org>: * Pull fixes for CVE-2018-10844 and CVE-2018-10845 from gnutls 3.5.19 <http://10.200.17.11/4.4-5/#2201705822002092449>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.4-5] eb4b79feba Bug #51709: gnutls28 3.5.8-5+deb9u5 doc/errata/staging/gnutls28.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) [4.4-5] 6a88b66fde Bug #51709: gnutls28 3.5.8-5+deb9u5 doc/errata/staging/gnutls28.yaml | 12 ++++++++++++ 1 file changed, 12 insertions(+)
<https://errata.software-univention.de/#/?erratum=4.4x661>