mono (3.2.8+dfsg-4ubuntu2.1) utopic-security; urgency=medium
* SECURITY UPDATE: TLS impersonation attack
- debian/patches/CVE-2015-2318.patch: add handshake state validation to
mcs/class/Mono.Security/Mono.Security.Protocol.Tls/ClientRecordProtocol.cs,
mcs/class/Mono.Security/Mono.Security.Protocol.Tls/Context.cs,
mcs/class/Mono.Security/Mono.Security.Protocol.Tls/RecordProtocol.cs,
mcs/class/Mono.Security/Mono.Security.Protocol.Tls/ServerRecordProtocol.cs.
- CVE-2015-2318
* SECURITY UPDATE: FREAK attack vulnerability
- debian/patches/CVE-2015-2319.patch: remove EXPORT ciphers from
mcs/class/Mono.Security/Mono.Security.Protocol.Tls/CipherSuiteFactory.cs,
mcs/class/Mono.Security/Mono.Security.Protocol.Tls/ClientRecordProtocol.cs,
mcs/class/Mono.Security/Mono.Security.Protocol.Tls/SslCipherSuite.cs,
mcs/class/Mono.Security/Mono.Security.Protocol.Tls/SslServerStream.cs,
mcs/class/Mono.Security/Mono.Security.Protocol.Tls/TlsCipherSuite.cs.
- CVE-2015-2319
* SECURITY UPDATE: SSLv2 support
- debian/patches/CVE-2015-2320.patch: remove client-side SSLv2 fallback in
mcs/class/Mono.Security/Mono.Security.Protocol.Tls/RecordProtocol.cs.
- CVE-2015-2320
Date: 2015-03-20 18:17:14.326630+00:00
Changed-By: Marc Deslauriers <[email protected]>
https://launchpad.net/ubuntu/+source/mono/3.2.8+dfsg-4ubuntu2.1
Sorry, changesfile not available.
--
Utopic-changes mailing list
[email protected]
Modify settings or unsubscribe at:
https://lists.canonical.com/mailman/listinfo/utopic-changes