|
Bugzilla – Full Text Bug Listing |
| Summary: | gnutls fails to verify certificate chains that contain an expired cross-signed intermediate in alternate chains | ||
|---|---|---|---|
| Product: | [openSUSE] openSUSE Distribution | Reporter: | Andreas Schwab <schwab> |
| Component: | Security | Assignee: | Vítězslav Čížek <vcizek> |
| Status: | RESOLVED FIXED | QA Contact: | E-mail List <qa-bugs> |
| Severity: | Major | ||
| Priority: | P5 - None | CC: | Andreas.Stieger, meissner, pmonrealgonzalez, security-team, vcizek |
| Version: | Leap 15.1 | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| Whiteboard: | |||
| Found By: | --- | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
Andreas Schwab
2020-06-03 13:40:22 UTC
https://build.opensuse.org/request/show/811395, but blocked on bug 1171565 (In reply to Andreas Stieger from comment #2) > https://build.opensuse.org/request/show/811395, but blocked on bug 1171565 I temporarily disabled the test in order to get the recent security fixes to Factory (bug 1172506, bug 1172663), so this bug will get fixed by request https://build.opensuse.org/request/show/812790. SUSE-SU-2020:1584-1: An update that solves one vulnerability and has one errata is now available. Category: security (important) Bug References: 1172461,1172506 CVE References: CVE-2020-13777 Sources used: SUSE Linux Enterprise Server for SAP 15 (src): gnutls-3.6.7-6.29.1 SUSE Linux Enterprise Server 15-LTSS (src): gnutls-3.6.7-6.29.1 SUSE Linux Enterprise Module for Basesystem 15-SP2 (src): gnutls-3.6.7-6.29.1 SUSE Linux Enterprise Module for Basesystem 15-SP1 (src): gnutls-3.6.7-6.29.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): gnutls-3.6.7-6.29.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): gnutls-3.6.7-6.29.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. openSUSE-SU-2020:0790-1: An update that solves one vulnerability and has one errata is now available. Category: security (important) Bug References: 1172461,1172506 CVE References: CVE-2020-13777 Sources used: openSUSE Leap 15.1 (src): gnutls-3.6.7-lp151.2.18.1 |