Summary: | net-libs/gnutls >=2.3.5 <2.4.1 gnutls_handshake() vulnerabilities (CVE-2008-2377) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Robert Buchholz (RETIRED) <rbu> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | trivial | CC: | dragonheart |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/2947 | ||
Whiteboard: | ~3? [noglsa] | ||
Package list: | Runtime testing required: | --- |
Description
Robert Buchholz (RETIRED)
2008-06-30 21:12:11 UTC
public as per urls detail http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/2948 will do ebuild soon gnutls-2.4.1 added gnutls-2.4.0 and gnutls-2.3.11.ebuild removed thanks Robert. description from upstream makes it seem though RCE is unlikely and DoS is fairly sure. Thanks, closing then. |