Hello, I've just released gnutls 3.0.11. This release fixes a timing attack possible in the DTLS code (report and patch by Nadhem Alfardan and Kenny Paterson).
* Version 3.0.11 (released 2012-01-06) ** libgnutls: Corrected functionality of gnutls_record_get_direction(). Reported by Philip Allison. ** libgnutls: Provide less timing information when decoding TLS/DTLS record packets. Patch by Nadhem Alfardan. ** API and ABI modifications: No changes since last version. Getting the Software ==================== GnuTLS may be downloaded from one of the GNU mirror sites or directly >From <ftp://ftp.gnu.org/gnu/gnutls/>. The list of GNU mirrors can be found at <http://www.gnu.org/prep/ftp.html> and a list of GnuTLS mirrors can be found at <http://www.gnu.org/software/gnutls/download.html>. Here are the XZ compressed sources: ftp://ftp.gnu.org/gnu/gnutls/gnutls-3.0.11.tar.xz http://ftp.gnu.org/gnu/gnutls/gnutls-3.0.11.tar.xz ftp://ftp.gnutls.org/pub/gnutls/gnutls-3.0.11.tar.xz Here are OpenPGP detached signatures signed using key 0x96865171: ftp://ftp.gnu.org/gnu/gnutls/gnutls-3.0.11.tar.xz.sig http://ftp.gnu.org/gnu/gnutls/gnutls-3.0.11.tar.xz.sig ftp://ftp.gnutls.org/pub/gnutls/gnutls-3.0.11.tar.xz.sig Note that it has been signed with my openpgp key: pub 3104R/96865171 2008-05-04 [expires: 2028-04-29] uid Nikos Mavrogiannopoulos <nmav <at> gnutls.org> uid Nikos Mavrogiannopoulos <n.mavrogiannopoulos <at> gmail.com> sub 2048R/9013B842 2008-05-04 [expires: 2018-05-02] sub 2048R/1404A91D 2008-05-04 [expires: 2018-05-02] regards, Nikos _______________________________________________ Help-gnutls mailing list [email protected] https://lists.gnu.org/mailman/listinfo/help-gnutls
