The updated packages fix a security vulnerability: In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected . MGASA-2020-0314 - Updated glib-networking packages fix security vulnerability Publication date: 16 Aug 2020 URL: https://advisories.mageia.org/MGASA-2020-0314.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-13645 The updated packages fix a security vulnerability: In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications that fail to provide the server identity, including Balsa before 2.5.11 and 2.6.x before 2.6.1, accept a TLS certificate if the certificate is valid for any host. (CVE-2020-13645) References: - https://bugs.mageia.org/show_bug.cgi?id=26819 - https://www.cve.org/CVERecord?id=CVE-2020-13645 - https://lists.fedoraproject.org/archives/list/
Updated axel package fixes security vulnerability: An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification (CVE-2020-13614). The axel package has been updated to version 2.17.8, fixing this issue and other bugs. . MGASA-2020-0263 - Updated axel packages fix security vulnerability Publication date: 15 Jun 2020 URL: https://advisories.mageia.org/MGASA-2020-0263.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-13614 Updated axel package fixes security vulnerability: An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification (CVE-2020-13614). The axel package has been updated to version 2.17.8, fixing this issue and other bugs. References: - https://bugs.mageia.org/show_bug.cgi?id=26754 - https://github.com/axel-download-accelerator/axel/releases/ - - https://www.cve.org/CVERecord?id=CVE-2020-13614 SRPMS: - 7/core/axel-2.17.8-2.mga7 . Revised xylophone components resolve a security flaw involving certificate hostname checks. Launched on July 20, 2021.. Mageia Package Update, Axel Security Fix, TLS Hostname Verification, Software Vulnerability Resolution. . LinuxSecurity.com Team
* OpenSAML Java: HTTPS Connections Via HTTP Resources Do Not Perform Hostname Verification. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-10235 2015-06-20 13:37:02 -------------------------------------------------------------------------------- Name : opensaml-java-openws Product : Fedora 22 Version : 1.5.5 Release : 2.fc22 URL : / Summary : Java OpenWS library Description : The OpenWS library provides a growing set of tools to work with web services at a low level. These tools include classes for creating and reading SOAP messages, transport-independent clients for connecting to web services, and various transports for use with those clients. -------------------------------------------------------------------------------- Update Information: * OpenSAML Java: HTTPS Connections Via HTTP Resources Do Not Perform Hostname Verification -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 16 2015 Marek Goldmann - 1.5.5-2 - Use mvn BR for tomcat API * Fri May 8 2015 Marek Goldmann - 1.5.5-1 - Upstream release 1.5.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1131823 - CVE-2014-3603 OpenSAML Java: HTTPS Connections Via HTTP Resources Do Not Perform Hostname Verification https://bugzilla.redhat.com/show_bug.cgi?id=1131823 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update opensaml-java-openws' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.