Bug#827620: netty: CVE-2016-4970: Infinite loop vulnerability when handling renegotiation using SslProvider.OpenSsl

2016-06-20 Thread Salvatore Bonaccorso
Hi Emmanuel, On Mon, Jun 20, 2016 at 10:07:04AM +0200, Emmanuel Bourg wrote: > Le 19/06/2016 à 00:18, tony mancill a écrit : > > > I haven't seen any information as to whether this vulnerability also > > affects the version in stable, 3.2.6. > > I don't think Jessie is affected, the vulnerable

Bug#827620: netty: CVE-2016-4970: Infinite loop vulnerability when handling renegotiation using SslProvider.OpenSsl

2016-06-20 Thread Emmanuel Bourg
Le 19/06/2016 à 00:18, tony mancill a écrit : > I haven't seen any information as to whether this vulnerability also > affects the version in stable, 3.2.6. I don't think Jessie is affected, the vulnerable code relies on netty-tcnative which is in testing/unstable only. The OpenSSL integration

Bug#827620: netty: CVE-2016-4970: Infinite loop vulnerability when handling renegotiation using SslProvider.OpenSsl

2016-06-18 Thread tony mancill
On 06/18/2016 11:51 AM, Salvatore Bonaccorso wrote: > Source: netty > Version: 1:4.0.36-2 > Severity: important > Tags: security upstream > > Hi, > > the following vulnerability was published for netty. Can you please > double-check this issue. According the upstream all versions > 4.0.0.Final -

Bug#827620: netty: CVE-2016-4970: Infinite loop vulnerability when handling renegotiation using SslProvider.OpenSsl

2016-06-18 Thread Salvatore Bonaccorso
Source: netty Version: 1:4.0.36-2 Severity: important Tags: security upstream Hi, the following vulnerability was published for netty. Can you please double-check this issue. According the upstream all versions 4.0.0.Final - 4.0.36.Final and 4.1.0.Final would be affected, and fixed in