Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Debian: 2023-510-04 Urgent: OpenSSL Vulnerability Exploit

slackware
Calendar Grey November 16, 2008
Dist Slackware Esm H88
A patch for GnuTLS in Slackware addresses problems with certificate chain validation. Resolves crashes linked to self-signed certs.
New gnutls packages are available for Slackware 12.0, 12.1, and -current to correctly fix the certificate chain verification issue that the upgrade to gnutls-2.6.1 attempted to fix

Summary

Here are the details from the Slackware 12.1 ChangeLog: patches/packages/gnutls-2.6.2-i486-1_slack12.1.tgz: Upgraded to gnutls-2.6.2. The security fix in gnutls-2.6.1 had a flaw in cases where the certificate chain contained only one self-signed certificate. This update fixes the issue.

Where Find New Packages

HINT: Getting slow download speeds from ftp.slackware.com? Give slackware.osuosl.org a try. This is another primary FTP site for Slackware that can be considerably faster than downloading directly from ftp.slackware.com.
Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating additional FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 12.0:
Updated package for Slackware 12.1:
Updated package for Slackware -current:

MD5 Signatures

Slackware 12.0 package: da23cbc35ceafc3de50c1d32e235a1f0 gnutls-2.6.2-i486-1_slack12.0.tgz
Slackware 12.1 package: f712d39374134e84629e2c2539f6c75f gnutls-2.6.2-i486-1_slack12.1.tgz
Slackware -current package: 7a838bc68ee6c9690a524658e0c3aefa gnutls-2.6.2-i486-1.tgz

Severity
important
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg gnutls-2.6.2-i486-1_slack12.1.tgz

Related News

Your message here