Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 922262 (CVE-2024-0553, CVE-2024-0567) - <net-libs/gnutls-3.8.3: Multiple vulnerabilities
Summary: <net-libs/gnutls-3.8.3: Multiple vulnerabilities
Status: IN_PROGRESS
Alias: CVE-2024-0553, CVE-2024-0567
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL:
Whiteboard: B3 [glsa cleanup]
Keywords:
Depends on: 940086
Blocks:
  Show dependency tree
 
Reported: 2024-01-17 03:58 UTC by Sam James
Modified: 2024-11-03 02:16 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2024-01-17 03:58:04 UTC
+** libgnutls: Fix more timing side-channel inside RSA-PSK key exchange
+   [GNUTLS-SA-2024-01-14, CVSS: medium] [CVE-2024-0553]
+
+** libgnutls: Fix assertion failure when verifying a certificate chain with a
+   cycle of cross signatures
+   [GNUTLS-SA-2024-01-09, CVSS: medium] [CVE-2024-0567]
+
Comment 1 Larry the Git Cow gentoo-dev 2024-01-17 04:45:20 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=53624e86f0aadc4368d66e013ed9ae4183877e40

commit 53624e86f0aadc4368d66e013ed9ae4183877e40
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2024-01-17 04:09:40 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2024-01-17 04:09:40 +0000

    net-libs/gnutls: add 3.8.3
    
    Bug: https://bugs.gentoo.org/922262
    Signed-off-by: Sam James <sam@gentoo.org>

 net-libs/gnutls/Manifest            |   2 +
 net-libs/gnutls/gnutls-3.8.3.ebuild | 149 ++++++++++++++++++++++++++++++++++++
 2 files changed, 151 insertions(+)
Comment 2 Larry the Git Cow gentoo-dev 2024-03-22 05:05:42 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=d807aa8600bb14d1777fcc4a8f0522f4674f46c8

commit d807aa8600bb14d1777fcc4a8f0522f4674f46c8
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2024-03-22 05:04:18 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2024-03-22 05:04:35 +0000

    net-libs/gnutls: drop 3.8.1-r1, 3.8.2
    
    Bug: https://bugs.gentoo.org/922262
    Signed-off-by: Sam James <sam@gentoo.org>

 net-libs/gnutls/Manifest               |   4 -
 net-libs/gnutls/gnutls-3.8.1-r1.ebuild | 146 ---------------------------------
 net-libs/gnutls/gnutls-3.8.2.ebuild    | 142 --------------------------------
 3 files changed, 292 deletions(-)