Package: libgnutls26 Version: 2.2.1-3 Severity: important User: [EMAIL PROTECTED] Usertags: origin-ubuntu
Hi folks, In debugging a regression introduced in OpenLDAP when switching from OpenSSL to GnuTLS in the latest upstream version, it's come to light that this is a bug in gnutls_x509_crt_get_subject_alt_name(), and a regression in GnuTLS 2.0.4 vs. GnuTLS 1.7: http://git.savannah.gnu.org/gitweb/?p=gnutls.git;a=commitdiff;h=deaa3ac31c2e83c292562ab66c1817c7ebc27048 Even though all other OIDs are returned with a size excluding any final newline, this change causes subject alt names to have a trailing newline appended - which, moreover, is added *after* the check for the buffer size, so this is a potential buffer overflow. This is discussed with OpenLDAP upstream at <http://www.openldap.org/its/index.cgi?findid=5361>. -- Steve Langasek Give me a lever long enough and a Free OS Debian Developer to set it on, and I can move the world. Ubuntu Developer http://www.debian.org/ [EMAIL PROTECTED] [EMAIL PROTECTED] -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

