Publishing details

Changelog

glib-networking (2.48.2-1~ubuntu16.04.2) xenial-security; urgency=medium

  * SECURITY UPDATE: Failure to validate TLS certificate hostname in
    certain conditions, contrary to documented behaviour
    - debian/patches/CVE-2020-13645.patch: Fail certificate verification
      when the server identity is missing. Based on upstream patch.
    - debian/patches/update-test-certs-for-gnutls.patch: Update the
      certificates used for unit test. Taken from upstream.
    - debian/patches/allow-insecure-md2-cert-in-test.patch: Allow insecure
      md2 certificate to used for one unit test. Taken from upstream.
    - CVE-2020-13645

 -- Alex Murray <email address hidden>  Tue, 23 Jun 2020 16:38:37 +0930

Available diffs

Builds

Built packages

Package files