16ea3ee784
Fixes the following security issue: * CVE-2020-13777: It was found that GnuTLS 3.6.4 introduced a regression in the TLS protocol implementation. This caused the TLS server to not securely construct a session ticket encryption key considering the application supplied secret, allowing a MitM attacker to bypass authentication in TLS 1.3 and recover previous conversations in TLS 1.2 Release announcement: https://lists.gnupg.org/pipermail/gnutls-help/2020-June/004648.html Signed-off-by: Stefan Sørensen <stefan.sorensen@spectralink.com> [yann.morin.1998@free.fr: two spaces in hash file] Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr> |
||
---|---|---|
.. | ||
Config.in | ||
gnutls.hash | ||
gnutls.mk |