gnutls 3.6.15

Daiki Ueno <[email protected]> Fri, 04 Sep 2020 09:29:11 +0200
Newsgroups gmane.network.gnutls.general,gmane.comp.encryption.gpg.gnutls.devel
Message-ID <[email protected]>
Hello,
 We've just released gnutls 3.6.15. This is a security and bug fix
release on the stable 3.6.x branch.

We'd like to thank everyone who contributed in this release:
Alexander Sosedkin, Daniel Lenski, Fiona Klute, Frantisek Krenzelok,
James Bottomley, Lei Maohui, Petr Pavlu, Steve Lhomme, and Vitezslav
Cizek.

The detailed list of changes follows:

* Version 3.6.15 (releases 2020-09-04)

** libgnutls: Fixed "no_renegotiation" alert handling at incorrect timing.
   The server sending a "no_renegotiation" alert in an unexpected timing,
   followed by an invalid second handshake was able to cause a TLS 1.3 client to
   crash via a null-pointer dereference. The crash happens in the application's
   error handling path, where the gnutls_deinit function is called after
   detecting a handshake failure (#1071).  [GNUTLS-SA-2020-09-04, CVSS: medium]

** libgnutls: If FIPS self-tests are failed, gnutls_fips140_mode_enabled() now
   indicates that with a false return value (!1306).

** libgnutls: Under FIPS mode, the generated ECDH/DH public keys are checked
   accordingly to SP800-56A rev 3 (!1295, !1299).

** libgnutls: gnutls_x509_crt_export2() now returns 0 upon success, rather than
   the size of the internal base64 blob (#1025). The new behavior aligns to the
   existing documentation.

** libgnutls: Certificate verification failue due to OCSP must-stapling is not
   honered is now correctly marked with the GNUTLS_CERT_INVALID flag
   (!1317). The new behavior aligns to the existing documentation.

** libgnutls: The audit log message for weak hashes is no longer printed twice
   (!1301).

** libgnutls: Fixed version negotiation when TLS 1.3 is enabled and TLS 1.2 is
   disabled in the priority string. Previously, even when TLS 1.2 is explicitly
   disabled with "-VERS-TLS1.2", the server still offered TLS 1.2 if TLS 1.3 is
   enabled (#1054).

** API and ABI modifications:
No changes since last version.

Getting the Software
====================

GnuTLS may be downloaded directly from <
ftp://ftp.gnutls.org/gcrypt/gnutls/>;.
A list of GnuTLS mirrors can be found at <
http://www.gnutls.org/download.html>

Here are the XZ compressed sources:

  https://www.gnupg.org/ftp/gcrypt/gnutls/v3.6/gnutls-3.6.15.tar.xz

Here are OpenPGP detached signatures signed using key 0x462225C3B46F34879FC8496CD605848ED7E69871:

  https://www.gnupg.org/ftp/gcrypt/gnutls/v3.6/gnutls-3.6.15.tar.xz.sig

Note that it has been signed with my openpgp key:
pub   rsa4096 2009-07-23 [SC] [expires: 2023-09-25]
      462225C3B46F34879FC8496CD605848ED7E69871
uid           [ultimate] Daiki Ueno <[email protected]>
uid           [ultimate] Daiki Ueno <[email protected]>
sub   rsa4096 2010-02-04 [E]

Regards,
-- 
Daiki Ueno, on behalf of the GnuTLS development team

_______________________________________________
Gnutls-help mailing list
[email protected]
http://lists.gnupg.org/mailman/listinfo/gnutls-help
signature.asc (application/pgp-signature, 832 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEERiIlw7RvNIefyEls1gWEjtfmmHEFAl9R7MsACgkQ1gWEjtfm
mHH2zhAAmCqcQI7O9m7WzyNsrjcmXdDq2nOv3JrLIj8dxB0krnzIDSRijJvnq5DG
WY490d1PCRZmtb+HqAc/9KISS83YiFzk8ECVnwFHxsZkVyL1mb885wdBp1jN/ItY
Wj3CZZDPtWvA5ksDwpdI/o1qCq35QHeDLd9U1oZ1YF1lXxXbmqd6Kw9K7TLGzaba
pJ0GNpcizFvDJK/MlvRviJ9ECcEzGWFxfnZYwKcF2Ufn4nMnzFRbjHkyf8TQ/F19
CvK4q9k9tL8N7ASam3lYZnA1fUrIt5GW3+G7cMtK3ZbAaaiX1+FhwdJavYVtQdMy
3rgBpSCM4t0dbJax70TTae45Q8qzsq/qleSKdGJ41iAvVT1NUSSPlcAplZ7CpYPL
c7icvRCJu5CqVldpIcP6r+JnhlJIsoXOqb9VLS/G8xYmFfMWY5W3H2kIZgoQxLXs
xCWYmJD+Lrgqbewg5R4kTSh6T2Ut7GlOWeN6oyjogYTsZeE48gHgg6rxRotPUzcG
99oXVsiXMo7KoI+P5MVLDC7Uzfb86cCpRNK9cvF+Assi1BeOV6/t7eAez1Rdx84c
/KcWcUENMYmWAVnkWSnEpOS+UcQQVzTTp2HQwaTVXc7xgstaL9q32aFyz6LJ2B7w
lxUO1spNf9e7dg6Shi4rK0UZ2X6MPNH6K/O0siANTZ1zMp1KN4g=
=qSIP
-----END PGP SIGNATURE-----