https://lists.gnupg.org/pipermail/gnutls-help/2020-September/004669.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-0ab6656303 2020-09-13 14:27:05.374615 --------------------------------------------------------------------------------Name : mingw-gnutls Product : Fedora 32 Version : 3.6.15 Release : 1.fc32 URL : http://www.gnutls.org/ Summary : MinGW GnuTLS TLS/SSL encryption library Description : GnuTLS TLS/SSL encryption library. This library is cross-compiled for MinGW. --------------------------------------------------------------------------------Update Information: https://lists.gnupg.org/pipermail/gnutls-help/2020-September/004669.html --------------------------------------------------------------------------------ChangeLog: * Fri Sep 4 2020 Michael Cronenworth - 3.6.15-1 - New upstream release 3.6.15 * Tue Jul 28 2020 Fedora Release Engineering - 3.6.14-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1875864 - CVE-2020-24659 mingw-gnutls: gnutls: Heap buffer overflow in handshake with no_renegotiation alert sent [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1875864 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-0ab6656303' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailinglist --
https://lists.gnupg.org/pipermail/gnutls-help/2020-March/004642.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-f90fb78f70 2020-05-08 02:43:36.320562 --------------------------------------------------------------------------------Name : mingw-gnutls Product : Fedora 32 Version : 3.6.13 Release : 1.fc32 URL : http://www.gnutls.org/ Summary : MinGW GnuTLS TLS/SSL encryption library Description : GnuTLS TLS/SSL encryption library. This library is cross-compiled for MinGW. --------------------------------------------------------------------------------Update Information: https://lists.gnupg.org/pipermail/gnutls-help/2020-March/004642.html --------------------------------------------------------------------------------ChangeLog: * Tue Mar 31 2020 Michael Cronenworth - 3.6.13-1 - New upstream release 3.6.13 --------------------------------------------------------------------------------References: [ 1 ] Bug #1619511 - CVE-2018-10844 mingw-gnutls: gnutls: HMAC-SHA-256 vulnerable to Lucky thirteen attack due to not enough dummy function calls [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1619511 [ 2 ] Bug #1619518 - CVE-2018-10845 mingw-gnutls: gnutls: HMAC-SHA-384 vulnerable to Lucky thirteen attack due to use of wrong constant [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1619518 [ 3 ] Bug #1619523 - CVE-2018-10846 mingw-gnutls: gnutls: "Just in Time" PRIME + PROBE cache-based side channel attack can lead to plaintext recovery [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1619523 [ 4 ] Bug #1821899 - CVE-2020-11501 mingw-gnutls: gnutls: DTLS client hello contains a random value of all zeroes [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1821899 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su-c 'dnf upgrade --advisory FEDORA-2020-f90fb78f70' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
New upstream release with security bug fix. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-15fb7deba0 2016-04-07 12:06:06.793002 -------------------------------------------------------------------------------- Name : python-rsa Product : Fedora 22 Version : 3.4.1 Release : 1.fc22 URL : http://stuvel.eu/rsa Summary : Pure-Python RSA implementation Description : Python-RSA is a pure-Python RSA implementation. It supports encryption and decryption, signing and verifying signatures, and key generation according to PKCS#1 version 1.5. It can be used as a Python library as well as on the command-line. -------------------------------------------------------------------------------- Update Information: New upstream release with security bug fix -------------------------------------------------------------------------------- References: [ 1 ] Bug #1170702 - Long-unfixed security vulnerabilities https://bugzilla.redhat.com/show_bug.cgi?id=1170702 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update python-rsa' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
libtasn1 4.4 release, fixing CVE-2015-2806. GnuTLS 3.3.14 release . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-5245 2015-04-01 21:10:51 -------------------------------------------------------------------------------- Name : mingw-gnutls Product : Fedora 21 Version : 3.3.14 Release : 1.fc21 URL : http://www.gnutls.org/ Summary : MinGW GnuTLS TLS/SSL encryption library Description : GnuTLS TLS/SSL encryption library. This library is cross-compiled for MinGW. -------------------------------------------------------------------------------- Update Information: libtasn1 4.4 release, fixing CVE-2015-2806. GnuTLS 3.3.14 release -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 1 2015 Michael Cronenworth - 3.3.14-1 - Update to 3.3.14 * Fri Jan 30 2015 Michael Cronenworth - 3.3.12-1 - Update to 3.3.12 * Mon Dec 15 2014 Michael Cronenworth - 3.3.11-1 - Update to 3.3.11-------------------------------------------------------------------------------- References: [ 1 ] Bug #1207192 - CVE-2015-2806 libtasn1: stack overflow in asn1_der_decoding https://bugzilla.redhat.com/show_bug.cgi?id=1207192 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update mingw-gnutls' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.