Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Fedora 28 GnuTLS Security Update: Critical DoS Issues Addressed

fedora
Calendar Grey April 4, 2019
Dist Fedora Esm H88
OpenSSL patch released for Ubuntu resolving severe memory leak and segmentation fault vulnerabilities discovered in earlier versions.
Security fix for CVE-2019-3829 and CVE-2019-3836

Summary

GnuTLS is a secure communications library implementing the SSL, TLS and DTLS

protocols and technologies around them. It provides a simple C language

application programming interface (API) to access the secure communications

protocols as well as APIs to parse and write X.509, PKCS #12, OpenPGP and

other required structures.

Security fix for CVE-2019-3829 and CVE-2019-3836

* Wed Mar 27 2019 Anderson Sasaki - 3.6.5-3

- Fixed CVE-2019-3829 (#1693210)

- Fixed CVE-2019-3836 (#1693214)

* Fri Jan 11 2019 Anderson Sasaki - 3.6.5-2

- Add explicit Requires for nettle >= 3.4.1

* Wed Jan 2 2019 Anderson Sasaki - 3.6.5-1

- Updated to upstream 3.6.5 release

- Fixed CVE-2018-16868 (#1659095)

* Tue Sep 25 2018 Nikos Mavrogiannopoulos - 3.6.4-1

- Updated to upstream 3.6.4 release

- Added support for the latest version of the TLS1.3 protocol

- The TLS1.3 protocol remains disabled by default

- Enabled SHA1 support as SHA1 deprecation is handled via the

fedora crypto policies.

* Thu Aug 16 2018 Nikos Mavrogiannopoulos - 3.6.3-4

- Fixed gnutls-cli input reading

- Ensure that we do not cause issues with version rollback detection

and TLS1.3.

* Tue Aug 7 2018 Nikos Mavrogiannopoulos - 3.6.3-3

- Fixed ECDSA public key import (#1612803)

* Thu Jul 26 2018 Nikos Mavrogiannopoulos - 3.6.3-2

- Backported regression fixes from 3.6.2

* Mon Jul 16 2018 Nikos Mavrogiannopoulos - 3.6.3-1

- Update to upstream 3.6.3 release

* Wed Jun 13 2018 Nikos Mavrogiannopoulos - 3.6.2-4

- Enable FIPS140-2 mode in Fedora

* Wed Jun 6 2018 Nikos Mavrogiannopoulos - 3.6.2-3

- Update to upstream 3.6.2 release

* Fri May 25 2018 David Abdurachmanov - 3.6.2-2

- Add missing BuildRequires: gnupg2 for gpgv2 in %prep

[ 1 ] Bug #1678411 - CVE-2019-3836 gnutls: invalid pointer access upon receiving async handshake messages

https://bugzilla.redhat.com/show_bug.cgi?id=1678411

[ 2 ] Bug #1677048 - CVE-2019-3829 gnutls: use-after-free/double-free in certificate verification

https://bugzilla.redhat.com/show_bug.cgi?id=1677048

su -c 'dnf upgrade --advisory FEDORA-2019-46df367eed' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 28
Version: 3.6.5
Release: 3.fc28
Summary: A TLS protocol implementation

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here