Gnutls version with with fix for CVE-2021-46848

Troy Hinckley <[email protected]> Mon, 13 Feb 2023 13:08:06 -0600
Newsgroups gmane.network.gnutls.general
Message-ID <b4a80a1f-fcf7-4c37-b01f-c5f49ad39cf3@Spark>
--===============3298068394077311352==
Content-Type: multipart/alternative; boundary="63ea8a9b_153ea438_4cc"

--63ea8a9b_153ea438_4cc
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

My company will not let us use gnutls due to=C2=A0CVE-2021-46848, which i=
mpacts libtasn1 versions less than 4.19. Gnutls is using version 4.16, an=
d hence is subject to this vulnerability. We attempted to build with 4.19=
, but the build failed. What would it take for Gnutls to upgrade to a sec=
urity compliant version of libtasn1=3F

- Troy Hinckley

--63ea8a9b_153ea438_4cc
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

<html xmlns=3D=22http://www.w3.org/1999/xhtml=22>
<head>
<title></title>
</head>
<body>
<div name=3D=22messageBodySection=22>
<div dir=3D=22auto=22>My company will not let us use gnutls due to&=23160=
;<a href=3D=22https://nvd.nist.gov/vuln/detail/CVE-2021-46848=22 target=3D=
=22=5Fblank=22>CVE-2021-46848</a>, which impacts libtasn1 versions less t=
han 4.19. Gnutls is using version 4.16, and hence is subject to this vuln=
erability. We attempted to build with 4.19, but the build failed. What wo=
uld it take for Gnutls to upgrade to a security compliant version of libt=
asn1=3F</div>
</div>
<div name=3D=22messageSignatureSection=22><br />
- Troy Hinckley</div>
</body>
</html>

--63ea8a9b_153ea438_4cc--



--===============3298068394077311352==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Gnutls-help mailing list
[email protected]
http://lists.gnupg.org/mailman/listinfo/gnutls-help

--===============3298068394077311352==--