-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - --- english/security/2016/dsa-3436.wml 2016-01-08 20:38:41.000000000 +0500 +++ russian/security/2016/dsa-3436.wml 2016-01-09 00:00:11.027849886 +0500 @@ -1,11 +1,12 @@ - -<define-tag description>security update</define-tag> +#use wml::debian::translation-check translation="1.2" maintainer="Lev Lamberov" +<define-tag description>обновление безопаÑноÑÑи</define-tag> <define-tag moreinfo> - -<p>Karthikeyan Bhargavan and Gaetan Leurent at INRIA discovered a flaw in - -the TLS 1.2 protocol which could allow the MD5 hash function to be used - -for signing ServerKeyExchange and Client Authentication packets during a - -TLS handshake. A man-in-the-middle attacker could exploit this flaw to - -conduct collision attacks to impersonate a TLS server or an - -authenticated TLS client.</p> +<p>ÐаÑÑикеÑн ÐÑ Ð°Ñгаван и ÐаÑÑан ÐÑÑен из INRIA обнаÑÑжили ÑÑзвимоÑÑÑ Ð² +пÑоÑоколе TLS 1.2, коÑоÑÐ°Ñ Ð¿Ð¾Ð·Ð²Ð¾Ð»ÑÐµÑ Ð¸ÑполÑзоваÑÑ Ñ ÑÑиÑÑÑÑÑÑ ÑÑнкÑÐ¸Ñ MD5 +Ð´Ð»Ñ Ð¿Ð¾Ð´Ð¿Ð¸ÑÑÐ²Ð°Ð½Ð¸Ñ Ð¿Ð°ÐºÐµÑов обмена клÑÑами Ñо ÑÑоÑÐ¾Ð½Ñ ÑеÑвеÑа и аÑÑенÑиÑикаÑии клиенÑа во вÑÐµÐ¼Ñ +TLS-ÑÑкопожаÑиÑ. РаÑÐ°ÐºÐ°Ñ Ð¿Ð¾ меÑÐ¾Ð´Ñ Ñеловек-в-ÑеÑедине ÑÑа ÑÑзвимоÑÑÑ Ð¼Ð¾Ð¶ÐµÑ +иÑполÑзоваÑÑÑÑ Ð´Ð»Ñ ÐºÐ¾Ð»Ð»Ð¸Ð·Ð¸Ð¾Ð½Ð½Ð¾Ð¹ аÑаки Ñ ÑелÑÑ Ð¸Ð¼Ð¸ÑаÑии ÑеÑвеÑа TLS или +аÑÑенÑиÑиÑиÑованного клиенÑа TLS.</p> <p>More information can be found at <a href='https://www.mitls.org/pages/attacks/SLOTH'>\ -----BEGIN PGP SIGNATURE-----
iQIcBAEBCgAGBQJWkAdxAAoJEF7nbuICFtKlcOkQAIHMxHqDQVkg+B3GkptF+SS7 VMLZOcrHCnCATta8iRoRjt8VCa4GYQYdCLdH43ETngTuIhlDaKA7JGhQ11JZxoJ1 DkJeFmh0znZnFM9487ebMfMPGXG2g5DottmyJVnrXTiRHUFaKQYtJj2eyQNRI5xS 4oee+fn3CV3E5zCoLzQkd//FBDyvRxzAjSdrciO5UaG87SXnd+Bv7GQyl2h0gVoi PU9w5FnKaI8B+8xx4af1fWs5EgV3AFyfSGciVWV7522sgand4IoBG65o7G6kOVQY eBDFlj4ssoAplYx98iio+iAw3MseaLxJPBjl1OWeF7SE6I9Mhq2YEyQHXVzdGalx 5wxRkQrbMURSr0ust+zK4tMJGCs2ai9xutdY4NZKBv391EoPAJW4FO13zGo8FXm7 hQoSsQW9HqRx+j9ZqJtjMbr3v8+AWeRjXUI7jEOIu7QglwDwqa8EBPifRT7YpE4Z O6mP+58cUhHlc8aqrm4xDGuP3XuIqVhAzMj5IkfJIGMdL1D2xKl9s8abKxHQ9hg6 19wVnA3uB2gQ8MBCQXU3slt1sC0Mi8Xt9H1NcbI9mgOcf5nLYZ2i9XFsixQARHN/ uxqYJESZjRjgD5BpFHKUbXxEMLoTPlvhU/dFBuZ6P1yl94FVP+tgBaWImG3HH4y9 4PWRee7X++2h5Prw1udm =KN/6 -----END PGP SIGNATURE-----

