#13337 closed enhancement (fixed)
gnutls-3.6.13 (GNUTLS-SA-2020-03-31, CVSS: high)
Reported by: | Bruce Dubbs | Owned by: | Bruce Dubbs |
---|---|---|---|
Priority: | high | Milestone: | 10.0 |
Component: | BOOK | Version: | SVN |
Severity: | normal | Keywords: | |
Cc: |
Description ¶
New point version.
Change History (7)
comment:2 by , 5 years ago
Priority: | normal → high |
---|---|
Summary: | gnutls-3.6.13 → gnutls-3.6.13 (GNUTLS-SA-2020-03-31, CVSS: high) |
comment:3 by , 5 years ago
GNUTLS-SA-2020-03-31 Severity High; flaw in DTLS protocol implementation It was found that GnuTLS 3.6.3 introduced a regression in the DTLS protocol implementation. This caused the DTLS client to not contribute any randomness to the DTLS negotiation breaking the security guarantees of the DTLS protocol. Recommendation: To address the issue found upgrade to GnuTLS 3.6.13 or later versions.
comment:4 by , 5 years ago
Owner: | changed from | to
---|---|
Status: | new → assigned |
Note:
See TracTickets
for help on using tickets.