Package: libgnutls26
Version: 2.2.1-3
Severity: important
User: [EMAIL PROTECTED]
Usertags: origin-ubuntu

Hi folks,

In debugging a regression introduced in OpenLDAP when switching from OpenSSL
to GnuTLS in the latest upstream version, it's come to light that this is a
bug in gnutls_x509_crt_get_subject_alt_name(), and a regression in GnuTLS
2.0.4 vs. GnuTLS 1.7:

  
http://git.savannah.gnu.org/gitweb/?p=gnutls.git;a=commitdiff;h=deaa3ac31c2e83c292562ab66c1817c7ebc27048

Even though all other OIDs are returned with a size excluding any final
newline, this change causes subject alt names to have a trailing newline
appended - which, moreover, is added *after* the check for the buffer size,
so this is a potential buffer overflow.

This is discussed with OpenLDAP upstream at
<http://www.openldap.org/its/index.cgi?findid=5361>.

-- 
Steve Langasek                   Give me a lever long enough and a Free OS
Debian Developer                   to set it on, and I can move the world.
Ubuntu Developer                                    http://www.debian.org/
[EMAIL PROTECTED]                                     [EMAIL PROTECTED]



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to