Changelog for
gnutls-2.12.23-21.el6.x86_64.rpm :
Mon Feb 13 13:00:00 2017 Nikos Mavrogiannopoulos
2.12.23-21
- Upgraded to 2.12.23 to incorporate multiple TLS 1.2 fixes
(#1326389, #1326073, #1323215, #1320982, #1328205, #1321112)
- Modified gnutls-serv to accept --sni-hostname (#1333521)
- Modified gnutls-serv to always reply with an alert message (#1327656)
- Removed support for DSA2 as it causes interoperability issues (#1321112)
- Allow sending and receiving certificates which were not in the
signature algorithms extension (#1328205)
- Removed support for EXPORT ciphersuites (#1337460)
- Raised the minimum acceptable DH size to 1024 (#1335924)
- Restricted the number of alert that can be received during handshake (#1388730)
- Added fixes for OpenPGP parsing issues (CVE-2017-5337, CVE-2017-5336, CVE-2017-5335)
- The exposed (but internal) crypto back-end registration API is deprecated and no
longer functional. The ABI is kept compatible (#1415682)
Wed Dec 9 13:00:00 2015 Nikos Mavrogiannopoulos 2.8.5-19
- Prevent downgrade attack to RSA-MD5 in TLS 1.2 server key exchange (#1289885)
Tue Mar 3 13:00:00 2015 Nikos Mavrogiannopoulos 2.8.5-18
- fix CVE-2015-0282 (#1198159)
- fix CVE-2015-0294 (#1198159)
Thu Jan 29 13:00:00 2015 Nikos Mavrogiannopoulos 2.8.5-17
- Corrected value initialization in mpi printing (#1129241)
Fri Jan 16 13:00:00 2015 Nikos Mavrogiannopoulos 2.8.5-16
- Check for expiry information in the CA certificates (#1159778)
Tue Dec 2 13:00:00 2014 Nikos Mavrogiannopoulos 2.8.5-15
- fix issue with integer padding in certificates and keys (#1036385)
Wed May 28 14:00:00 2014 Nikos Mavrogiannopoulos 2.8.5-14
- fix session ID length check (#1102025)
Wed Feb 26 13:00:00 2014 Nikos Mavrogiannopoulos 2.8.5-13
- fix CVE-2014-0092 (#1069891)
Mon May 27 14:00:00 2013 Tomas Mraz 2.8.5-12
- fix CVE-2013-2116 - fix DoS regression in CVE-2013-1619
upstream patch (#966754)
Thu Feb 21 13:00:00 2013 Tomas Mraz 2.8.5-11
- fix CVE-2013-1619 - fix TLS-CBC timing attack (#908238)
Mon Oct 29 13:00:00 2012 Tomas Mraz 2.8.5-10
- fix the build of the info manual
Wed Oct 10 14:00:00 2012 Tomas Mraz 2.8.5-9
- documentation fixes in gnutls_priority_init(3), gnutls-serv(1),
and gnutls-cli-debug(1) manual pages (#648297, #807746)
- add fallback to import the private keys as PKCS#8 (#745242)
- silence the strict aliasing warnings
Thu May 3 14:00:00 2012 Tomas Mraz 2.8.5-7
- more TLS-1.2 compatibility fixes (TLS-1.2 stays disabled by default)
Wed Mar 21 13:00:00 2012 Tomas Mraz 2.8.5-5
- fix CVE-2012-1573 - security issue in packet parsing (#805432)
- fix CVE-2011-4128 - buffer overflow in gnutls_session_get_data() (#752308)
- TLS-1.2 certificate request compatibility fix
Wed Jun 2 14:00:00 2010 Tomas Mraz 2.8.5-4
- add support for safe renegotiation CVE-2009-3555 (#533125)
Thu Jan 28 13:00:00 2010 Tomas Mraz 2.8.5-3
- drop superfluous rpath from binaries
- do not call autoreconf during build
- specify the license on utils subpackage
- do not create static libraries (#556052)
Fri Dec 18 13:00:00 2009 Tomas Mraz 2.8.5-2
- disable experimental openssl compatibility code (#460310)
Thu Dec 3 13:00:00 2009 Dennis Gregorovic - 2.8.5-1.1
- Rebuilt for RHEL 6
Mon Nov 2 13:00:00 2009 Tomas Mraz 2.8.5-1
- upgrade to a new upstream version
Wed Sep 23 14:00:00 2009 Tomas Mraz 2.8.4-1
- upgrade to a new upstream version
Fri Aug 14 14:00:00 2009 Tomas Mraz 2.8.3-1
- upgrade to a new upstream version
Fri Jul 24 14:00:00 2009 Fedora Release Engineering - 2.8.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild
Wed Jun 10 14:00:00 2009 Tomas Mraz 2.8.1-1
- upgrade to a new upstream version
Wed Jun 3 14:00:00 2009 Tomas Mraz 2.8.0-1
- upgrade to a new upstream version
Mon May 4 14:00:00 2009 Tomas Mraz 2.6.6-1
- upgrade to a new upstream version - security fixes
Tue Apr 14 14:00:00 2009 Tomas Mraz 2.6.5-1
- upgrade to a new upstream version, minor bugfixes only
Fri Mar 6 13:00:00 2009 Tomas Mraz 2.6.4-1
- upgrade to a new upstream version
Tue Feb 24 13:00:00 2009 Fedora Release Engineering - 2.6.3-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild
Mon Dec 15 13:00:00 2008 Tomas Mraz 2.6.3-1
- upgrade to a new upstream version
Thu Dec 4 13:00:00 2008 Tomas Mraz 2.6.2-1
- upgrade to a new upstream version
Tue Nov 11 13:00:00 2008 Tomas Mraz 2.4.2-3
- fix chain verification issue CVE-2008-4989 (#470079)
Thu Sep 25 14:00:00 2008 Tomas Mraz 2.4.2-2
- add guile subpackage (#463735)
- force new libtool through autoreconf to drop unnecessary rpaths
Tue Sep 23 14:00:00 2008 Tomas Mraz 2.4.2-1
- new upstream version
Tue Jul 1 14:00:00 2008 Tomas Mraz 2.4.1-1
- new upstream version
- correct the license tag
- explicit --with-included-opencdk not needed
- use external lzo library, internal not included anymore
Tue Jun 24 14:00:00 2008 Tomas Mraz 2.4.0-1
- upgrade to latest upstream
Tue May 20 14:00:00 2008 Tomas Mraz 2.0.4-3
- fix three security issues in gnutls handshake - GNUTLS-SA-2008-1
(#447461, #447462, #447463)
Mon Feb 4 13:00:00 2008 Joe Orton 2.0.4-2
- use system libtasn1
Tue Dec 4 13:00:00 2007 Tomas Mraz 2.0.4-1
- upgrade to latest upstream
Tue Aug 21 14:00:00 2007 Tomas Mraz 1.6.3-2
- license tag fix
Wed Jun 6 14:00:00 2007 Tomas Mraz 1.6.3-1
- upgrade to latest upstream (#232445)
Tue Apr 10 14:00:00 2007 Tomas Mraz 1.4.5-2
- properly require install-info (patch by Ville Skyttä)
- standard buildroot and use dist tag
- add COPYING and README to doc
Wed Feb 7 13:00:00 2007 Tomas Mraz 1.4.5-1
- new upstream version
- drop libtermcap-devel from buildrequires
Thu Sep 14 14:00:00 2006 Tomas Mraz 1.4.1-2
- detect forged signatures - CVE-2006-4790 (#206411), patch
from upstream
Tue Jul 18 14:00:00 2006 Tomas Mraz - 1.4.1-1
- upgrade to new upstream version, only minor changes
Wed Jul 12 14:00:00 2006 Jesse Keating - 1.4.0-1.1
- rebuild
Wed Jun 14 14:00:00 2006 Tomas Mraz - 1.4.0-1
- upgrade to new upstream version (#192070), rebuild
of dependent packages required
Tue May 16 14:00:00 2006 Tomas Mraz - 1.2.10-2
- added missing buildrequires
Mon Feb 13 13:00:00 2006 Tomas Mraz - 1.2.10-1
- updated to new version (fixes CVE-2006-0645)
Fri Feb 10 13:00:00 2006 Jesse Keating - 1.2.9-3.2
- bump again for double-long bug on ppc(64)
Tue Feb 7 13:00:00 2006 Jesse Keating - 1.2.9-3.1
- rebuilt for new gcc4.1 snapshot and glibc changes
Tue Jan 3 13:00:00 2006 Jesse Keating 1.2.9-3
- rebuilt
Fri Dec 9 13:00:00 2005 Tomas Mraz 1.2.9-2
- replaced
*-config scripts with calls to pkg-config to
solve multilib conflicts
Wed Nov 23 13:00:00 2005 Tomas Mraz 1.2.9-1
- upgrade to newest upstream
- removed .la files (#172635)
Sun Aug 7 14:00:00 2005 Tomas Mraz 1.2.6-1
- upgrade to newest upstream (rebuild of dependencies necessary)
Mon Jul 4 14:00:00 2005 Tomas Mraz 1.0.25-2
- split the command line tools to utils subpackage
Sat Apr 30 14:00:00 2005 Tomas Mraz 1.0.25-1
- new upstream version fixes potential DOS attack
Sat Apr 23 14:00:00 2005 Tomas Mraz 1.0.24-2
- readd the version script dropped by upstream
Fri Apr 22 14:00:00 2005 Tomas Mraz 1.0.24-1
- update to the latest upstream version on the 1.0 branch
Wed Mar 2 13:00:00 2005 Warren Togami 1.0.20-6
- gcc4 rebuild
Tue Jan 4 13:00:00 2005 Ivana Varekova 1.0.20-5
- add gnutls Requires zlib-devel (#144069)
Mon Nov 8 13:00:00 2004 Colin Walters 1.0.20-4
- Make gnutls-devel Require libgcrypt-devel
Tue Sep 21 14:00:00 2004 Jeff Johnson 1.0.20-3
- rebuild with release++, otherwise unchanged.
Tue Sep 7 14:00:00 2004 Jeff Johnson 1.0.20-2
- patent tainted SRP code removed.
Sun Sep 5 14:00:00 2004 Jeff Johnson 1.0.20-1
- update to 1.0.20.
- add --with-included-opencdk --with-included-libtasn1
- add --with-included-libcfg --with-included-lzo
- add --disable-srp-authentication.
- do \"make check\" after build.
Fri Mar 21 13:00:00 2003 Jeff Johnson 0.9.2-1
- upgrade to 0.9.2
Tue Jun 25 14:00:00 2002 Jeff Johnson 0.4.4-1
- update to 0.4.4.
Fri Jun 21 14:00:00 2002 Tim Powers
- automated rebuild
Sat May 25 14:00:00 2002 Jeff Johnson 0.4.3-1
- update to 0.4.3.
Tue May 21 14:00:00 2002 Jeff Johnson 0.4.2-1
- update to 0.4.2.
- change license to LGPL.
- include splint annotations patch.
Tue Apr 2 14:00:00 2002 Nalin Dahyabhai 0.4.0-1
- update to 0.4.0
Thu Jan 17 13:00:00 2002 Nalin Dahyabhai 0.3.2-1
- update to 0.3.2
Thu Jan 10 13:00:00 2002 Nalin Dahyabhai 0.3.0-1
- add a URL
Thu Dec 20 13:00:00 2001 Nalin Dahyabhai
- initial package