Re: Critical bug in GnuTLS

2014-03-07 Thread g
On 03/05/14 07:26, Matthew Miller wrote: On Wed, Mar 05, 2014 at 12:01:04AM +, Patrick O'Callaghan wrote: http://arstechnica.com/security/2014/03/critical-crypto-bug-leaves-linux-hundreds-of-apps-open-to-eavesdropping/ Putting aside the slightly hysterical tone of the article, this is appe

Re: Critical bug in GnuTLS

2014-03-05 Thread Susi Lehtola
On Wed, 5 Mar 2014 11:29:23 + "Patrick O'Callaghan" wrote: > On Wed, Mar 5, 2014 at 10:28 AM, Ed Greshko wrote: > > On 03/05/14 18:21, Patrick O'Callaghan wrote: > >> On Wed, Mar 5, 2014 at 1:26 AM, Matthew Miller > >> wrote: > >>> https://admin.fedoraproject.org/updates/FEDORA-2014-3413/g

Re: Critical bug in GnuTLS

2014-03-05 Thread Patrick O'Callaghan
On Wed, Mar 5, 2014 at 10:28 AM, Ed Greshko wrote: > On 03/05/14 18:21, Patrick O'Callaghan wrote: >> On Wed, Mar 5, 2014 at 1:26 AM, Matthew Miller >> wrote: >>> https://admin.fedoraproject.org/updates/FEDORA-2014-3413/gnutls-3.1.20-4.fc20 >>> https://admin.fedoraproject.org/updates/FEDORA-2014

Re: Critical bug in GnuTLS

2014-03-05 Thread Heinz Diehl
On 05.03.2014, Ed Greshko wrote: > Well The article pointed to by poc states Yes, you're right. Sorry for the noise! -- users mailing list users@lists.fedoraproject.org To unsubscribe or change subscription options: https://admin.fedoraproject.org/mailman/listinfo/users Fedora Code of

Re: Critical bug in GnuTLS

2014-03-05 Thread Ed Greshko
On 03/05/14 18:21, Patrick O'Callaghan wrote: > On Wed, Mar 5, 2014 at 1:26 AM, Matthew Miller > wrote: >> https://admin.fedoraproject.org/updates/FEDORA-2014-3413/gnutls-3.1.20-4.fc20 >> https://admin.fedoraproject.org/updates/FEDORA-2014-3363/gnutls-3.1.20-4.fc19 >> >> These need testing and ka

Re: Critical bug in GnuTLS

2014-03-05 Thread Patrick O'Callaghan
On Wed, Mar 5, 2014 at 1:26 AM, Matthew Miller wrote: > https://admin.fedoraproject.org/updates/FEDORA-2014-3413/gnutls-3.1.20-4.fc20 > https://admin.fedoraproject.org/updates/FEDORA-2014-3363/gnutls-3.1.20-4.fc19 > > These need testing and karma. AFAIK 3.1.20 is not the bugfixed version. It need

Re: Critical bug in GnuTLS

2014-03-04 Thread Ed Greshko
On 03/05/14 14:18, Heinz Diehl wrote: > On 05.03.2014, Matthew Miller wrote: > >> https://admin.fedoraproject.org/updates/FEDORA-2014-3413/gnutls-3.1.20-4.fc20 >> https://admin.fedoraproject.org/updates/FEDORA-2014-3363/gnutls-3.1.20-4.fc19 > Do they fix the bug? > Well The article pointed t

Re: Critical bug in GnuTLS

2014-03-04 Thread Heinz Diehl
On 05.03.2014, Matthew Miller wrote: > https://admin.fedoraproject.org/updates/FEDORA-2014-3413/gnutls-3.1.20-4.fc20 > https://admin.fedoraproject.org/updates/FEDORA-2014-3363/gnutls-3.1.20-4.fc19 Do they fix the bug? -- users mailing list users@lists.fedoraproject.org To unsubscribe or change

Re: Critical bug in GnuTLS

2014-03-04 Thread Digimer
On 04/03/14 08:26 PM, Matthew Miller wrote: On Wed, Mar 05, 2014 at 12:01:04AM +, Patrick O'Callaghan wrote: http://arstechnica.com/security/2014/03/critical-crypto-bug-leaves-linux-hundreds-of-apps-open-to-eavesdropping/ Putting aside the slightly hysterical tone of the article, this is app

Re: Critical bug in GnuTLS

2014-03-04 Thread Matthew Miller
On Wed, Mar 05, 2014 at 12:01:04AM +, Patrick O'Callaghan wrote: > http://arstechnica.com/security/2014/03/critical-crypto-bug-leaves-linux-hundreds-of-apps-open-to-eavesdropping/ > Putting aside the slightly hysterical tone of the article, this is > appears to be a real bug with potentially se

Critical bug in GnuTLS

2014-03-04 Thread Patrick O'Callaghan
http://arstechnica.com/security/2014/03/critical-crypto-bug-leaves-linux-hundreds-of-apps-open-to-eavesdropping/ Putting aside the slightly hysterical tone of the article, this is appears to be a real bug with potentially serious implications. I see that Koji has an updated rpm for F21 and wonder