Thursday, January 9, 2020

[USN-4233-1] GnuTLS update

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl4XLPoACgkQZWnYVadE
vpNDohAAvET1I06ENVuB4KF5p91wz/i17FNdzOiS/abx53ksZzsrzEDZ3slB+e1g
R5zFQqgttj11S2Z9jhTHUTZqy5Qca1lAzTGb0OV2B1dwbgQ881xmf5BmdC3BFuuD
/tGLmtqiD3379/YmMw+X2L7ojwvyH5Ub7NDm92Vy6rF3P5bLOEWK9JMiKHuJGpmS
ELugqzvAv37cwAiEWwHG3Z8ww7ymEq/GSN1P7wrAOvCgE3AktuBmMgJxAXl4d4yq
H2a6wA5cgp0Chi/SlWUgFpYhevt1zTthCJZ/QqlBa5ZffCgzxUIPPli/ebvkP/2m
9dSep+73+Y0LE4aRXCzSQB2S8OOobtZ1eUqUnpkaRb5jXE9EF7fKtRuga4UG/b3q
UbQSrAw4dQsM1yahQLS2l2uv8J5qmd2jQPQLjGt7GcibsqSvZWf7ZYJfyzdhaq+U
6gLRwQLotHG+HBXWSLZ+fs+YFYozAmEHz5L0sV7cUyKc78d7ybfRliBY2zutWSE1
CsqH3/ZlkcjXivmTFx5n3hvTMBIq537T0ZQGcLgG3yHgKKPpaDTRogWKYXvCY93l
J34IYOmdcMxOGBYJ6x5WmTCnd8BgBlOD/tuUJyc88bbGBR34kgOjBLAxLOE+bjAz
T8gh+7+0gzbiua2R4RDZDX0V/PMEmwAruuT0QmsWfK4kavboAP8=
=ysdQ
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-4233-1
January 09, 2020

gnutls28 update
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

SHA1 has been marked as untrusted in GnuTLS.

Software Description:
- gnutls28: GNU TLS library

Details:

As a security improvement, this update marks SHA1 as being untrusted for
digital signature operations.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
libgnutls30 3.5.18-1ubuntu1.2

Ubuntu 16.04 LTS:
libgnutls30 3.4.10-4ubuntu1.6

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4233-1
https://launchpad.net/bugs/1858691

Package Information:
https://launchpad.net/ubuntu/+source/gnutls28/3.5.18-1ubuntu1.2
https://launchpad.net/ubuntu/+source/gnutls28/3.4.10-4ubuntu1.6

No comments:

Post a Comment