Multiple security vulnerabilities have been discovered in GnuTLS, a library implementing the TLS and SSL protocols, which may result in execution of arbitrary code, denial of service, information leak, certificate misuse, name constraint bypass, authentication bypass, revocation bypass or timing side-channel attacks.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6281-1
Tim Scheckenbach reported a flaw in GnuTLS, a library implementing the TLS and SSL protocols. Processing of specially crafted certificates containing a large number of name constraints may result in denial of service (resource exhaustion). For the oldstable distribution (bookworm), this problem has been fixed. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6140-1
Multiple security issues were discovered in GNU TLS, which could result in denial of service. For the stable distribution (bookworm), these problems have been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5962-1
A flaw was reported in the TLS session ticket key construction in GnuTLS, a library implementing the TLS and SSL protocols. The flaw caused the TLS server to not securely construct a session ticket encryption key considering the application supplied secret, allowing a . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4697-1
Kurt Roeckx discovered that decoding a specific certificate with very long DistinguishedName (DN) entries leads to double free. A remote attacker can take advantage of this flaw by creating a specially crafted certificate that, when processed by an application compiled against . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3334-1
Get the latest Linux and open source security news straight to your inbox.