-
gnutls26 (2.8.3-2) unstable; urgency=low
* [ debian/patches/15_openpgp.diff ] The CVE-2009-2730 patch broke
openpgp connections.
-- Michael Bienia <email address hidden> Mon, 24 Aug 2009 13:13:07 +0100
-
gnutls26 (2.8.3-1) unstable; urgency=high
* New upstream version.
+ Stops hardcoding a hard dependency on the versions of gcrypt and tasn it
was built against. Closes: #540449
+ Fixes CVE-2009-2730, a vulnerability related to NUL bytes in X.509
certificate name fields. Closes: #541439 GNUTLS-SA-2009-4
http://lists.gnu.org/archive/html/help-gnutls/2009-08/msg00011.html
* Drop 15_chainverify_expiredcert.diff, included upstream.
* Urgency high, since 541439 applies to testing, too.
gnutls26 (2.8.1-2) unstable; urgency=low
[ Simon Josefsson ]
* Remove cruft in rules file.
* Remove patches/15_tasn1inpc.diff, not needed.
[ Andreas Metzler ]
* Finally add an entry to the NEWS.Debian file concerning the deprecation of
RSA-MD2 and RSA-MD5 for signature verification. Closes: #514578
* Upload to unstable.
* 15_chainverify_expiredcert.diff: New patch, pulled from upstream GIT.
Fix testsuite error caused by expired certificate.
gnutls26 (2.8.1-1) experimental; urgency=low
* New upstream stable release.
gnutls26 (2.7.14-1) experimental; urgency=low
* [debian/control] set section setting of source package to libs instead of
devel.
* New upstream version.
+ Drop debian/patches/16_symbolversioning_fix.diff, included upstream.
+ Bump shlibs, new symbols added.
gnutls26 (2.7.12-1) experimental; urgency=low
* Fix typo in changelog. Closes: #526427
* New upstream release.
+ Does not ship the scripts libgnutls-extra-config and libgnutls-config
and the .m4 snippet to use it anymore. Please switch to pkg-config or
standard autoconf test. Drop manpages and
both patches/13_lessdeps_gnutls-config.diff and
patches/13_lessdeps_gnutls-config.diff from the debian diff.
+ Update remaining patches.
+ Bump shlibs, new symbols added.
* [patches/16_symbolversioning_fix.diff] Since gnutls_x509_crq_set_key was
already present in 2.6.x it needs to be versioned GNUTLS_1_4 instead of
GNUTLS_2_8.
* New upstream uses separate ./configure scripts for the different
libraries. Invoke the main ./configure script with
--cache-file=$(CURDIR)/config.cache to speed things up.
-- Bhavani Shankar <email address hidden> Mon, 17 Aug 2009 16:13:34 +0100
-
gnutls26 (2.6.6-1ubuntu1) karmic; urgency=low
* SECURITY UPDATE: fix improper handling of '\0' in Common Name (CN) and
Subject Alternative Name (SAN) in X.509 certificates (LP: #413136)
- debian/patches/16_CVE-2009-2730.diff: verify length of CN and SAN
are what we expect and error out if either contains an embedded \0
- CVE-2009-2730
-- Jamie Strandboge <email address hidden> Fri, 14 Aug 2009 09:55:54 -0500
-
gnutls26 (2.6.6-1) unstable; urgency=high
* use @LTLIBTASN1@ instead of @LIBTASN1@ in Libs.private of *.pc.in. This
way lib-link.m4 gives us -ltasn1 instead of /usr/lib/libtasn1.so.
* New upstream security release.
+ libgnutls: Corrected double free on signature verification failure.
GNUTLS-SA-2009-1 CVE-2009-1415
+ libgnutls: Fix DSA key generation. Noticed when investigating the
previous GNUTLS-SA-2009-1 problem. All DSA keys generated using GnuTLS
2.6.x are corrupt. See the advisory for more details.
GNUTLS-SA-2009-2 CVE-2009-1416
+ libgnutls: Check expiration/activation time on untrusted certificates.
Before the library did not check activation/expiration times on
certificates, and was documented as not doing so.
GNUTLS-SA-2009-3 CVE-2009-1417
* The former two issues only apply to gnutls 2.6.x. The latter is a
brehavior change, add a NEWS.Debian file to document it.
-- Ubuntu Archive Auto-Sync <email address hidden> Fri, 01 May 2009 20:30:36 +0100
-
gnutls26 (2.6.5-1) unstable; urgency=low
* Sync sections in debian/control with override file. libgnutls26-dbg is
section debug, guile-gnutls is section lisp.
* New upstream version. (Needed for Libtasn1-3 2.0)
* New patch 15_tasn1inpc.diff. Make sure libtasn1 is listed in Libs.private.
* Standards-Version: 3.8.1, no changes required.
gnutls26 (2.6.4-2) unstable; urgency=low
* Upload to unstable.
* Merge changelog entries from unstable and experimental.
gnutls26 (2.6.4-1) experimental; urgency=low
* New upstream version.
gnutls26 (2.6.3-1) experimental; urgency=low
* New upstream version.
+ Corrects bug gnutls-cli which caused a rehandshake request
to be ignored. Closes: #396867
* Drop debian/patches/21_GNUTLS-SA-2008-3.fix.patch (included upstream)
gnutls26 (2.6.2-2) experimental; urgency=low
* 21_GNUTLS-SA-2008-3.fix.patch Another fix for the verification fix. Some
correct certificate chains were not recognized as verified.
Closes: #507633
* [lintian] Add ${misc:Depends} to multiple dendency lines.
gnutls26 (2.6.2-1) experimental; urgency=low
* New upstream version.
+ Fixes certification verifaction error CVE-2008-4989. Closes: #505360
+ Drop 20_fix_501077.diff.
* ia64 has guile-1.8 nowadays, let's try building the guile-gnutls wrappper
there.
* Add Simon Josefsson to uploaders.
gnutls26 (2.6.0-1) experimental; urgency=low
* New upstream stable release.
* Add debian/patches/20_fix_501077.diff to fix an out of bound access in
gnutls-openssl. (Thanks, Thomas Viehmann). Closes: #501077
gnutls26 (2.5.9-1) experimental; urgency=low
* New upstream development version.
* Bump shlibs.
-- Ubuntu Archive Auto-Sync <email address hidden> Wed, 29 Apr 2009 00:12:58 +0100
-
gnutls26 (2.4.2-6) unstable; urgency=medium
* New patches, syncing with 2.4.3 upstream oldstable release:
+ 24_intermedcertificate.patch If a non-root certificate ist trusted
gnutls certificateificate verification stops there instead of checking
up to the root of the certificate chain.
+ 22_whitespace.patch - Whitespace only changes, to make it possible to
apply upstream fixes without manual changes.
+ 25_bufferoverrun.patch. Fix buffer overrun bug in
gnutls_x509_crt_list_import.
http://news.gmane.org/find-root.php?message_id=%3c000001c91d6e%2463059c90%242910d5b0%24%40com%3e
-- Jamie Strandboge <email address hidden> Fri, 20 Feb 2009 20:10:15 +0000