Dr. Werner Fink 2020-06-19 10:49:39 +00:00 committed by Git OBS Bridge
parent 91b7c1edc5
commit 2f9d54775f

View File

@ -4,6 +4,7 @@ Mon Jun 15 15:05:52 UTC 2020 - Werner Fink <werner@suse.de>
- Update to 1.14.3 - bug-fix release (boo#1172906, boo#1172935, - Update to 1.14.3 - bug-fix release (boo#1172906, boo#1172935,
CVE-2020-14093, CVE-2020-14154) CVE-2020-14093, CVE-2020-14154)
* Prevent possible IMAP MITM via PREAUTH response. * Prevent possible IMAP MITM via PREAUTH response.
* expired where certs not properly rejected with GnuTLS
* Fix GnuTLS interactive prompt short-circuiting. * Fix GnuTLS interactive prompt short-circuiting.
* Abort GnuTLS certificate check if a cert in the chain is rejected. * Abort GnuTLS certificate check if a cert in the chain is rejected.
* Fix GnuTLS tls_verify_peers() checking. * Fix GnuTLS tls_verify_peers() checking.