Summary: | <net-libs/gnutls-3.2.5: libdane buffer overflow (CVE-2013-4466) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Mikle Kolyada (RETIRED) <zlogene> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | trivial | CC: | alonbl, crypto+disabled |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://seclists.org/oss-sec/2013/q4/173 | ||
Whiteboard: | ~3 [noglsa] | ||
Package list: | Runtime testing required: | --- |
Description
Mikle Kolyada (RETIRED)
![]() ![]() ![]() ![]() gnutls-3.2.5 in tree (In reply to Alon Bar-Lev from comment #1) > gnutls-3.2.5 in tree thanks, cleanup old vuln. versions, please, (In reply to Mikle Kolyada from comment #2) > (In reply to Alon Bar-Lev from comment #1) > > gnutls-3.2.5 in tree > > thanks, cleanup old vuln. versions, please, this is non stable package, and not trivial changes since last, we should allow people to revert. The fact that it's unstable means that there is the possibility of breakage. Leave it for a little while if you want, but the old versions do need to go. (In reply to Alon Bar-Lev from comment #3) > this is non stable package, and not trivial changes since last, we should > allow people to revert. to clarify - we want 3.2.3 and 3.2.4 go from tree, not 2.x <3.2.5 seems to be gone from tree, closing. |