Bug#752610: lynx: Can connect to CVE-2014-1959 test site

2014-06-29 Thread Andreas Metzler
Control: reassign 752610 lynx-cur 2.8.8dev.12-2 On 2014-06-27 Kurt Roeckx k...@roeckx.be wrote: On Fri, Jun 27, 2014 at 08:05:41PM +0200, Andreas Metzler wrote: On 2014-06-26 Kurt Roeckx k...@roeckx.be wrote: On Thu, Jun 26, 2014 at 07:58:04PM +0200, Andreas Metzler wrote: [...] indeed an

Processed: Re: Bug#752610: lynx: Can connect to CVE-2014-1959 test site

2014-06-29 Thread Debian Bug Tracking System
Processing control commands: reassign 752610 lynx-cur 2.8.8dev.12-2 Bug #752610 [lynx-cur, libgnutls26] lynx: Can connect to CVE-2014-1959 test site Bug reassigned from package 'lynx-cur, libgnutls26' to 'lynx-cur'. Ignoring request to alter found versions of bug #752610 to the same values

Bug#752610: lynx: Can connect to CVE-2014-1959 test site

2014-06-27 Thread Kurt Roeckx
On Fri, Jun 27, 2014 at 08:05:41PM +0200, Andreas Metzler wrote: On 2014-06-26 Kurt Roeckx k...@roeckx.be wrote: On Thu, Jun 26, 2014 at 07:58:04PM +0200, Andreas Metzler wrote: [...] indeed an important difference comes up when comparing gnutls-cli -p 443 gnutls.notary.icsi.berkeley.edu

Bug#752610: lynx: Can connect to CVE-2014-1959 test site

2014-06-27 Thread Andreas Metzler
On 2014-06-26 Kurt Roeckx k...@roeckx.be wrote: On Thu, Jun 26, 2014 at 07:58:04PM +0200, Andreas Metzler wrote: [...] indeed an important difference comes up when comparing gnutls-cli -p 443 gnutls.notary.icsi.berkeley.edu --x509cafile \ /etc/ssl/certs/ca-certificates.crt with

Bug#752610: lynx: Can connect to CVE-2014-1959 test site

2014-06-26 Thread Andreas Metzler
On 2014-06-25 Kurt Roeckx k...@roeckx.be wrote: Package: lynx-cur, libgnutls26 Severity: serious Tags: security Hi, There is a test site for checking the gnutls bug: https://gnutls.notary.icsi.berkeley.edu/ I can connect to it and get the message: If you see this without getting a

Bug#752610: lynx: Can connect to CVE-2014-1959 test site

2014-06-26 Thread Kurt Roeckx
On Thu, Jun 26, 2014 at 07:58:04PM +0200, Andreas Metzler wrote: On 2014-06-25 Kurt Roeckx k...@roeckx.be wrote: Package: lynx-cur, libgnutls26 Severity: serious Tags: security Hi, There is a test site for checking the gnutls bug: https://gnutls.notary.icsi.berkeley.edu/ I can

Bug#752610: lynx: Can connect to CVE-2014-1959 test site

2014-06-25 Thread Kurt Roeckx
Package: lynx-cur, libgnutls26 Severity: serious Tags: security Hi, There is a test site for checking the gnutls bug: https://gnutls.notary.icsi.berkeley.edu/ I can connect to it and get the message: If you see this without getting a certificate error you are vulnerable against the GnuTLS