Bug#929907: libgnutls30: Connections to older GnUTLS servers break

Andreas Metzler ametzler at bebt.de
Sat Jun 8 18:08:01 BST 2019


On 2019-06-04 Andreas Metzler <ametzler at bebt.de> wrote:
> On 2019-06-03 Dominik George <natureshadow at debian.org> wrote:
[...]
> >    pwgen 16383 | gnutls-cli --no-ca-verification --port 5556 localhost

> > From a size of 16383 bytes onwards, I get:

> > |<1>| Received packet with illegal length: 16385
> > |<1>| Discarded message[1] due to invalid decryption
> > *** Fatal error: A TLS record packet with invalid length was received.
> > *** Server has terminated the connection abnormally.
[...]
> Will try a bisect to check why .8 works, but might not have time before
> weekend.

Hello Dominik,

the attached cherry-picked patch fixes the gnutls-cli reproducer. - Does
it also help for your original problem?

TIA, cu Andreas
-- 
`What a good friend you are to him, Dr. Maturin. His other friends are
so grateful to you.'
`I sew his ears on from time to time, sure'
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 40_ext-record_size_limit-distinguish-sending-and-receiv.patch
Type: text/x-diff
Size: 11718 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-gnutls-maint/attachments/20190608/64e1ea36/attachment.patch>


More information about the Pkg-gnutls-maint mailing list