Debian Security Advisory
DLA-364-1 gnutls26 -- LTS security update
- Date Reported:
- 09 Dec 2015
- Affected Packages:
- gnutls26
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2015-8313.
- More information:
-
Hanno Böck discovered that GnuTLS, a library implementing the TLS and SSL protocols, incorrectly validated the first padding byte in CBC modes. A remote attacker can possibly take advantage of this flaw to perform a padding oracle attack.
For Debian 6
Squeeze
, this issue has been fixed in gnutls26 version 2.8.6-1+squeeze6. We recommend you to upgrade your gnutls26 packages.