Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Slackware 14.1: 2014-062-01 Critical: Gnutls Certificate Bypass Issue

slackware
Calendar Grey March 4, 2014
Dist Slackware Esm H88
Updated gnutls versions are now accessible for Slackware to mitigate a significant security vulnerability and promote secure operation.
New gnutls packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue

Summary

Here are the details from the Slackware 14.1 ChangeLog: patches/packages/gnutls-3.1.22-i486-1_slack14.1.txz: Upgraded. Fixed a security issue where a specially crafted certificate could bypass certificate validation checks. For more information, see: https://www.cve.org/CVERecord?id=CVE-2014-0092 (* Security fix *) Thanks to mancha for backporting the patch for Slackware 13.0, 13.1, 13.37, and 14.0!

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 13.0:
Updated package for Slackware x86_64 13.0:
Updated package for Slackware 13.1:
Updated package for Slackware x86_64 13.1:
Updated package for Slackware 13.37:
Updated package for Slackware x86_64 13.37:
Updated package for Slackware 14.0:
Updated package for Slackware x86_64 14.0:
Updated package for Slackware 14.1:
Updated package for Slackware x86_64 14.1:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:

MD5 Signatures

Slackware 13.0 package: 20c1c57f2f807e0a825fea258e393247 gnutls-2.8.4-i486-3_slack13.0.txz
Slackware x86_64 13.0 package: 053267a6b918756369d9d9b95182f7a9 gnutls-2.8.4-x86_64-3_slack13.0.txz
Slackware 13.1 package: 412c5bcc3cf65fc57cc117459be3e2fe gnutls-2.8.6-i486-3_slack13.1.txz
Slackware x86_64 13.1 package: 58b0d65ecd1c457fb484cc98c7cbb327 gnutls-2.8.6-x86_64-3_slack13.1.txz
Slackware 13.37 package: bf93e57188e4bf8b3f4978507c035847 gnutls-2.10.5-i486-3_slack13.37.txz
Slackware x86_64 13.37 package: e8975f0e48d3f15687fbf407db6d9740 gnutls-2.10.5-x86_64-3_slack13.37.txz
Slackware 14.0 package: b6b4b1f1756cc7857ddb430c8c52cbb0 gnutls-3.0.31-i486-3_slack14.0.txz
Slackware x86_64 14.0 package: d4de153fe1a64c1d1291e0242489957d gnutls-3.0.31-x86_64-3_slack14.0.txz
Slackware 14.1 package: a91ba05b256cceff004ae2cdc08e3239 gnutls-3.1.22-i486-1_slack14.1.txz
Slackware x86_64 14.1 package: 8a372d2d52292805ffa59cc8825f47b3 gnutls-3.1.22-x86_64-1_slack14.1.txz
Slackware -current package: 86da62d25631d150279d3b0df8ce13af n/gnutls-3.1.22-i486-1.txz
Slackware x86_64 -current package: b91ff54d6a6109ce24669c5cdb0ffc86 n/gnutls-3.1.22-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg gnutls-3.1.22-i486-1_slack14.1.txz

Related News

Your message here