You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa mbedtls

Sigurnosni nedostaci programskog paketa mbedtls

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2018-9817f1dafa
2018-02-28 16:43:48.675001
——————————————————————————–

Name : mbedtls
Product : Fedora 26
Version : 2.7.0
Release : 1.fc26
URL : https://tls.mbed.org/
Summary : Light-weight cryptographic and SSL/TLS library
Description :
Mbed TLS is a light-weight open source cryptographic and SSL/TLS
library written in C. Mbed TLS makes it easy for developers to include
cryptographic and SSL/TLS capabilities in their (embedded)
applications with as little hassle as possible.
FOSS License Exception: https://tls.mbed.org/foss-license-exception

——————————————————————————–
Update Information:

– Update to 2.7.0 Release notes: https://tls.mbed.org/tech-
updates/releases/mbedtls-2.7.0-2.1.10-and-1.3.22-released Security Advisory:
https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-
advisory-2018-01
——————————————————————————–
References:

[ 1 ] Bug #1544729 – CVE-2017-18187 CVE-2018-0487 CVE-2018-0488 mbedtls: various flaws [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1544729
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade mbedtls’ at the command line.
For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

——————————————————————————–
Fedora Update Notification
FEDORA-2018-eb58dc8a6f
2018-02-28 17:09:26.405658
——————————————————————————–

Name : mbedtls
Product : Fedora 27
Version : 2.7.0
Release : 1.fc27
URL : https://tls.mbed.org/
Summary : Light-weight cryptographic and SSL/TLS library
Description :
Mbed TLS is a light-weight open source cryptographic and SSL/TLS
library written in C. Mbed TLS makes it easy for developers to include
cryptographic and SSL/TLS capabilities in their (embedded)
applications with as little hassle as possible.
FOSS License Exception: https://tls.mbed.org/foss-license-exception

——————————————————————————–
Update Information:

– Update to 2.7.0 Release notes: https://tls.mbed.org/tech-
updates/releases/mbedtls-2.7.0-2.1.10-and-1.3.22-released Security Advisory:
https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-
advisory-2018-01
——————————————————————————–
References:

[ 1 ] Bug #1533435 – Please enable pthread support for mbedtls
https://bugzilla.redhat.com/show_bug.cgi?id=1533435
[ 2 ] Bug #1544729 – CVE-2017-18187 CVE-2018-0487 CVE-2018-0488 mbedtls: various flaws [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1544729
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade mbedtls’ at the command line.
For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

AutorPetar Bertok
Cert idNCERT-REF-2018-03-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostaci jezgre operacijskog sustava

Otkriveni su sigurnosni nedostaci u jezgri operacijskog sustava SUSE. Otkriveni nedostaci potencijalnim napadačima omogućuju otkrivanje osjetljivih informacija, pristup nealociranoj memoriji,...

Close