Bug#782776: CVE-2015-3308

Andreas Metzler ametzler at bebt.de
Sat Apr 18 17:22:46 UTC 2015


On 2015-04-17 Moritz Muehlenhoff <jmm at debian.org> wrote:
> Hi Andreas,
> this was assigned CVE-2015-3308:
> http://www.openwall.com/lists/oss-security/2015/04/15/6  

> gnutls in wheezy or squeeze should not be affected, the
> code was introduced in 3.3 (please double-check).

> This doesn't seem severe, could you fix this in the first
> jessie point release?

Hello,

I will push an upload to unstable to get some free testing and will try
to get this fixed in jessie, either with a separate upload or (if jessie
is delayed) an unblock.

cu Andreas
-- 
`What a good friend you are to him, Dr. Maturin. His other friends are
so grateful to you.'
`I sew his ears on from time to time, sure'



More information about the Pkg-gnutls-maint mailing list