Lucene search

K
debianDebianDEBIAN:2F52B94AF1F3F28544124123CB62D3AF:F9725
HistoryJun 02, 2014 - 7:51 a.m.

gnutls26 security update

2014-06-0207:51:19
lists.debian.org
8

0.661 Medium

EPSS

Percentile

97.9%

Package : gnutls26
Version : 2.8.6-1+squeeze4
CVE ID : CVE-2014-3466

Joonas Kuorilehto discovered that GNU TLS performed insufficient
validation of session IDs during TLS/SSL handshakes. A malicious
server could use this to execute arbitrary code or perform denial
or service.