Re: [SECURITY] gnutls

2017-05-03 Thread Yaakov Selkowitz
On 2017-03-24 14:00, Yaakov Selkowitz wrote: On 2017-03-10 16:01, Yaakov Selkowitz wrote: On 2017-02-22 12:46, Yaakov Selkowitz wrote: On 2016-09-26 14:13, Yaakov Selkowitz wrote: On 2016-09-26 02:00, Yaakov Selkowitz wrote: Dr. Volker, Two security issues have been reported in GnuTLS:

Re: [SECURITY] gnutls

2017-03-24 Thread Yaakov Selkowitz
On 2017-03-10 16:01, Yaakov Selkowitz wrote: On 2017-02-22 12:46, Yaakov Selkowitz wrote: On 2016-09-26 14:13, Yaakov Selkowitz wrote: On 2016-09-26 02:00, Yaakov Selkowitz wrote: Dr. Volker, Two security issues have been reported in GnuTLS:

Re: [SECURITY] gnutls

2017-03-10 Thread Yaakov Selkowitz
On 2017-02-22 12:46, Yaakov Selkowitz wrote: On 2016-09-26 14:13, Yaakov Selkowitz wrote: On 2016-09-26 02:00, Yaakov Selkowitz wrote: Dr. Volker, Two security issues have been reported in GnuTLS: https://www.gnutls.org/security.html#GNUTLS-SA-2016-2

Re: [SECURITY] gnutls

2017-02-22 Thread Yaakov Selkowitz
On 2016-09-26 14:13, Yaakov Selkowitz wrote: On 2016-09-26 02:00, Yaakov Selkowitz wrote: Dr. Volker, Two security issues have been reported in GnuTLS: https://www.gnutls.org/security.html#GNUTLS-SA-2016-2 https://www.gnutls.org/security.html#GNUTLS-SA-2016-3 At this point, I think the best

Re: [SECURITY] gnutls

2016-09-26 Thread Yaakov Selkowitz
On 2016-09-26 02:00, Yaakov Selkowitz wrote: Dr. Volker, Two security issues have been reported in GnuTLS: https://www.gnutls.org/security.html#GNUTLS-SA-2016-2 https://www.gnutls.org/security.html#GNUTLS-SA-2016-3 At this point, I think the best way to proceed would be to: 1) release 3.3.24

[SECURITY] gnutls

2016-09-26 Thread Yaakov Selkowitz
Dr. Volker, Two security issues have been reported in GnuTLS: https://www.gnutls.org/security.html#GNUTLS-SA-2016-2 https://www.gnutls.org/security.html#GNUTLS-SA-2016-3 At this point, I think the best way to proceed would be to: 1) release 3.3.24 with the patch for the latter, then; 2)

[SECURITY] gnutls (CVE-2015-6251)

2015-08-24 Thread Yaakov Selkowitz
Dr. Volker, http://www.gnutls.org/security.html#GNUTLS-SA-2015-3 Fix: upgrade to 3.3.17, which is supposed to be ABI-compatible with 3.2 (minus the removal of the libgnutls-xssl wrapper library, which is unused AFAIK), OR add the following patch to 3.2.20:

Re: [SECURITY] gnutls (CVE-2015-6251)

2015-08-24 Thread Dr. Volker Zell
Yaakov Selkowitz writes: Dr. Volker, Hi http://www.gnutls.org/security.html#GNUTLS-SA-2015-3 Fix: upgrade to 3.3.17, which is supposed to be ABI-compatible with 3.2 (minus the removal of the libgnutls-xssl wrapper library, which is unused AFAIK), OR add the

Re: [SECURITY] gnutls, lzo2

2014-11-04 Thread Corinna Vinschen
Hi Volker, On Oct 22 10:14, Dr. Volker Zell wrote: Yaakov Selkowitz writes: Dr. Volker Zell, A few of your packages are awaiting updates, some of which are security-related: * gnutls - 3.2.19 [SECURITY] * lcms2 - 2.6 * libtasn1 - 3.9 * liblzo2 -

Re: [SECURITY] gnutls, lzo2

2014-10-22 Thread Dr. Volker Zell
Yaakov Selkowitz writes: Dr. Volker Zell, A few of your packages are awaiting updates, some of which are security-related: * gnutls - 3.2.19 [SECURITY] * lcms2 - 2.6 * libtasn1 - 3.9 * liblzo2 - 2.0.8 [SECURITY] * neon - 0.30.1 * openldap - 2.4.40

[SECURITY] gnutls, lzo2

2014-10-20 Thread Yaakov Selkowitz
Dr. Volker Zell, A few of your packages are awaiting updates, some of which are security-related: * gnutls - 3.2.19 [SECURITY] * lcms2 - 2.6 * libtasn1 - 3.9 * liblzo2 - 2.0.8 [SECURITY] * neon - 0.30.1 * openldap - 2.4.40 * tzcode - 2014h Any chance you will be able to update your packages

Re: [SECURITY] gnutls

2012-06-26 Thread Yaakov (Cygwin/X)
On Wed, 2012-05-02 at 01:01 -0500, Yaakov (Cygwin/X) wrote: On 2012-03-26 04:31, Dr. Volker Zell wrote: Yaakov writes: A security vulnerability has just been announced for gnutls (CVE-2012-1573). This can be fixed by updating to 2.12.18. Yaakov can you update your

Re: [SECURITY] gnutls

2012-03-26 Thread Dr. Volker Zell
Yaakov writes: A security vulnerability has just been announced for gnutls (CVE-2012-1573). This can be fixed by updating to 2.12.18. Yaakov can you update your p11-kit package. I could use it in a new gnutls build. checking for P11_KIT... configure: error: Package requirements

[SECURITY] gnutls

2012-03-24 Thread Yaakov (Cygwin/X)
A security vulnerability has just been announced for gnutls (CVE-2012-1573). This can be fixed by updating to 2.12.18. Yaakov

Re: SECURITY: gnutls

2011-10-18 Thread Corinna Vinschen
On Oct 17 20:45, Chris Sutcliffe wrote: On 16 October 2011 14:49, Yaakov (Cygwin/X) wrote: Dr. Volker Zell, gnutls 2.8.6 is susceptible to CVE-2009-3555.  This has been fixed since 2.10.0, but the current stable releases are 2.12.11 (ABI-compatible with 2.8.6) and 3.0.4 (which breaks

Re: SECURITY: gnutls

2011-10-18 Thread Dr. Volker Zell
Chris Sutcliffe writes: On 16 October 2011 14:49, Yaakov (Cygwin/X) wrote: Dr. Volker Zell, gnutls 2.8.6 is susceptible to CVE-2009-3555.  This has been fixed since 2.10.0, but the current stable releases are 2.12.11 (ABI-compatible with 2.8.6) and 3.0.4 (which

Re: SECURITY: gnutls

2011-10-17 Thread Chris Sutcliffe
On 16 October 2011 14:49, Yaakov (Cygwin/X) wrote: Dr. Volker Zell, gnutls 2.8.6 is susceptible to CVE-2009-3555.  This has been fixed since 2.10.0, but the current stable releases are 2.12.11 (ABI-compatible with 2.8.6) and 3.0.4 (which breaks ABI compatibility).  For now, please release

[SECURITY] gnutls

2009-09-14 Thread Yaakov (Cygwin/X)
Dr. Volker Zell, gnutls suffers from several security vulnerabilities[1]. Could you add this to your list to update when you have a chance? [1] http://www.gentoo.org/security/en/glsa/glsa-200905-04.xml Yaakov