Mangelnde Rechteprüfung in mbed TLS
ID: | FEDORA-2017-382c240580 |
Distribution: | Fedora |
Plattformen: | Fedora 26 |
Datum: | So, 3. September 2017, 10:30 |
Referenzen: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14032 |
Applikationen: | mbed TLS |
Originalnachricht |
|
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-382c240580 2017-09-02 19:24:01.578663 -------------------------------------------------------------------------------- Name : mbedtls Product : Fedora 26 Version : 2.6.0 Release : 1.fc26 URL : https://tls.mbed.org/ Summary : Light-weight cryptographic and SSL/TLS library Description : Mbed TLS is a light-weight open source cryptographic and SSL/TLS library written in C. Mbed TLS makes it easy for developers to include cryptographic and SSL/TLS capabilities in their (embedded) applications with as little hassle as possible. FOSS License Exception: https://tls.mbed.org/foss-license-exception -------------------------------------------------------------------------------- Update Information: - Update to 2.6.0 Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.6.0-2.1.9-and-1.3.21-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2017-02 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1487120 - CVE-2017-14032 mbedtls: Bypass peer authentication https://bugzilla.redhat.com/show_bug.cgi?id=1487120 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade mbedtls' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org |