The _gnutls_x509_verify_certificate fix
simon at josefsson.org
Wed Nov 12 11:16:08 CET 2008
Simon Josefsson <simon at josefsson.org> writes:
>> Applying this to 2.4.2 this does away with the crash, however it does
>> not fix the advisory anymore. (The way to reproduce described in
>> works again.
> Really? I think the patch should solve both the crash and the
> advisory. Are you sure you used the right library?
I've tested the patch and it appears to fix both the crash and the
vulnerability. Please test it again. I've prepared a daily build of
v2.6.2 containing that fix:
More information about the Gnutls-devel