[SECURITY] Fedora 8 Update: gnutls-1.6.3-5.fc8
updates at fedoraproject.org
updates at fedoraproject.org
Wed Nov 12 03:00:29 UTC 2008
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-9600
2008-11-12 01:59:08
--------------------------------------------------------------------------------
Name : gnutls
Product : Fedora 8
Version : 1.6.3
Release : 5.fc8
URL : http://www.gnutls.org/
Summary : A TLS protocol implementation
Description :
GnuTLS is a project that aims to develop a library which provides a secure
layer, over a reliable transport layer. Currently the GnuTLS library implements
the proposed standards by the IETF's TLS working group.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Nov 11 2008 Tomas Mraz <tmraz at redhat.com> 1.6.3-5
- fix chain verification issue CVE-2008-4989 (#470079)
* Fri Jun 20 2008 Tomas Mraz <tmraz at redhat.com> 1.6.3-4
- backported fix for compression support (#451952)
* Tue May 20 2008 Tomas Mraz <tmraz at redhat.com> 1.6.3-3
- fix three security issues in gnutls handshake - GNUTLS-SA-2008-1
(#447461, #447462, #447463)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #470079 - CVE-2008-4989 gnutls: certificate chain verification flaw
https://bugzilla.redhat.com/show_bug.cgi?id=470079
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update gnutls' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
More information about the package-announce
mailing list