Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
12894eb7 by Salvatore Bonaccorso at 2018-09-19T19:46:25Z
Update information for CVE-2018-10846/gnutls28

- - - - -
6c5a7e68 by Salvatore Bonaccorso at 2018-09-19T19:46:35Z
Wrap one note

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -16047,10 +16047,12 @@ CVE-2018-10847 (prosody before versions 0.10.2, 
0.9.14 is vulnerable to an ...)
        NOTE: 
https://prosody.im/security/advisory_20180531/issue1147-0.10.1.patch (0.10.1)
        NOTE: https://prosody.im/security/advisory_20180531/issue1147-0.9.patch 
(0.9.x)
 CVE-2018-10846 (A cache-based side channel in GnuTLS implementation that leads 
to ...)
+       [experimental] - gnutls28 3.6.3-1
        - gnutls28 <unfixed>
        - gnutls26 <removed>
        NOTE: https://gitlab.com/gnutls/gnutls/merge_requests/657
-       NOTE: The proposed fix is to introduce a new option to force 
encrypt-then-mac instead of correcting the issue.
+       NOTE: The proposed fix is to introduce a new option to force 
encrypt-then-mac
+       NOTE: instead of correcting the issue.
        NOTE: https://eprint.iacr.org/2018/747
 CVE-2018-10845 (It was found that the GnuTLS implementation of HMAC-SHA-384 
was ...)
        - gnutls28 <unfixed>



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/compare/7d7ff4871232f5de26bc7af8b613f77f73a2a3b6...6c5a7e68c81a63097e37c90b7b0ea79aef667e5a

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/compare/7d7ff4871232f5de26bc7af8b613f77f73a2a3b6...6c5a7e68c81a63097e37c90b7b0ea79aef667e5a
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
debian-security-tracker-commits@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to