* SECURITY UPDATE: fix improper handling of '\0' in Common Name (CN) and
Subject Alternative Name (SAN) in X.509 certificates (LP: #413136)
- debian/patches/26_CVE-2009-2730.diff: verify length of CN and SAN
are what we expect and error out if either contains an embedded \0
- CVE-2009-2730
This bug was fixed in the package gnutls26 - 2.4.2-6ubuntu0.1
---------------
gnutls26 (2.4.2-6ubuntu0.1) jaunty-security; urgency=low
* SECURITY UPDATE: fix improper handling of '\0' in Common Name (CN) and patches/ 26_CVE- 2009-2730. diff: verify length of CN and SAN
Subject Alternative Name (SAN) in X.509 certificates (LP: #413136)
- debian/
are what we expect and error out if either contains an embedded \0
- CVE-2009-2730
-- Jamie Strandboge <email address hidden> Fri, 14 Aug 2009 14:01:09 -0500