it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Moritz Muehlenhoff <jmm AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 5349-1] gnutls28 security update
- Date: Tue, 14 Feb 2023 18:54:44 +0000
- Authentication-results: mail.piratenpartei.de; dkim=none; spf=none (mail.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 82.195.75.100) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"; dmarc=none
- List-archive: https://lists.debian.org/msgid-search/Y+vY9OheSc+h7J1g AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From:Date :Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=r6aBqRWe7cwoVVFAfN/5RF6aXihHwS1zjtPaK/Sh0cY=; b=PB ix7GEncTW6KJbFHoU7Nb9Ingc6I7UQzcoMxmESqbhmqVocyKUmNKeU9eZOASIl+cMepH7GXsTkS1P jGHFG0U8Omp6G7SUerVQbzcpbPKWm7np8AaNebBspdIaB+6Vc8gvI43/YLjmjYwbJecBDtIhJHCjo te/O4c+9ctXYGgApIhKReW2L6YhHDFSCzEEj/uGvvCDPYASAud8aFTabvdWod3eqjrvrmMfHoPbjS KkG+/pPWMw8nfp8mMi1RUXd5ON1k6+ibRRKaB8k627gTx/pJ1LISYCD1aAULKDUcEJEBk3dVjTdOc TTEczZG0n+3G55YgLxE3JxSCNLpZL7Yg==;
- Old-return-path: <jmm AT seger.debian.org>
- Priority: urgent
- Resent-date: Tue, 14 Feb 2023 18:55:12 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <b6uROaJGPfL.A.xvG.Qk96jB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-5349-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
February 14, 2023 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : gnutls28
CVE ID : CVE-2023-0361
Hubert Kario discovered a timing side channel in the RSA decryption
implementation of the GNU TLS library.
For the stable distribution (bullseye), this problem has been fixed in
version 3.7.1-5+deb11u3.
We recommend that you upgrade your gnutls28 packages.
For the detailed security status of gnutls28 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/gnutls28
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmPr180ACgkQEMKTtsN8
TjYiww/7BLMYnCqWIWB8YC+TFWAF6HEVXCFLTy/ksXO7tc/pglydOrzajIRnRb1J
imOwMCcK19vJT3JLMQsbVXztpeGIYhLa8GR/c718NGmhkEV7z+NmFIS+eSi2Urt/
Yb6m9InN5RPbEbGoMVCxnFdAqHTob0rEo+pgNekUtIJ+M/qQHCTz/UijjevoETUu
a+u2E7yjafT1SMPMdI+NemwZxfEpoNYafK9VBCtXVyEKWW/f149rQU7O825HTQ4o
ZxRzTVWjJlXfwRj+HLmOqUQhAEEaR3tznFx8+bMDYCgyL7AaEnBJ+ygHZRwDy7ui
UaVqgpIXF4jB3Kw1j5b0rQokO/wTNYioFCOmZwkSobe4ODKcTw0VVoYFj/EhbgBH
q8EEVy8ZeBnon33wTTW6bXtUtqUmz0rXKyGVB6JUPiEbeGtLlScswqAKE70KG7uF
5pPKpPUu4VK9EfceqC6ld/m0tUg393QwVGoo8fK6RXauNWKAvM2I9qarLoGF9GMq
FgewlSVdg2N91ChUWb6/XdQ0EYg+dB9lNmfG9wVsqa7013Lj3O32JQz8s8QJ1qtr
26MoZMDx1SB/XNwLhby8UlUiQmYFSvnS+lLx5BbBVNSORPGXWt14pa6Mzv1YK8wZ
w+Z7aobGptaOwCeZ8cVAGBCYaDVnmOni+1c8MAKnYUbCrC1kx/E=
=qFL8
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 5349-1] gnutls28 security update, Moritz Muehlenhoff, 14.02.2023
Archiv bereitgestellt durch MHonArc 2.6.24.