A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.
{
"binaries": [
{
"binary_version": "3.7.3-4ubuntu1.5",
"binary_name": "gnutls-bin"
},
{
"binary_version": "3.7.3-4ubuntu1.5",
"binary_name": "guile-gnutls"
},
{
"binary_version": "3.7.3-4ubuntu1.5",
"binary_name": "libgnutls-dane0"
},
{
"binary_version": "3.7.3-4ubuntu1.5",
"binary_name": "libgnutls-openssl27"
},
{
"binary_version": "3.7.3-4ubuntu1.5",
"binary_name": "libgnutls28-dev"
},
{
"binary_version": "3.7.3-4ubuntu1.5",
"binary_name": "libgnutls30"
},
{
"binary_version": "3.7.3-4ubuntu1.5",
"binary_name": "libgnutlsxx28"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_version": "3.8.3-1.1ubuntu3.1",
"binary_name": "gnutls-bin"
},
{
"binary_version": "3.8.3-1.1ubuntu3.1",
"binary_name": "libgnutls-dane0t64"
},
{
"binary_version": "3.8.3-1.1ubuntu3.1",
"binary_name": "libgnutls-openssl27t64"
},
{
"binary_version": "3.8.3-1.1ubuntu3.1",
"binary_name": "libgnutls28-dev"
},
{
"binary_version": "3.8.3-1.1ubuntu3.1",
"binary_name": "libgnutls30t64"
}
],
"availability": "No subscription required"
}