[gnutls-devel] GnuTLS | SECURITY: use-after-free in PSK binder calculation (#1151)

Read-only notification of GnuTLS library development activities gnutls-devel at lists.gnutls.org
Thu Jun 10 18:40:17 CEST 2021




Andreas Metzler commented on a discussion: https://gitlab.com/gnutls/gnutls/-/issues/1151#note_598368491

 Boya Xiao @xiaoboya wrote
> I installed gnutls(3.7.1-3) in Debian 10.9,but the result for trivy show CRITICAL(CVE-2021-20231, CVE-2021-20232)

Afaict trivy has a list of packages and versions which fix the vulnerabilties. It does not *check* whether the issue is fixed or not but simply consults the list. And the list is probably outdated.

-- 
Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/issues/1151#note_598368491
You're receiving this email because of your account on gitlab.com.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.gnupg.org/pipermail/gnutls-devel/attachments/20210610/3a82749b/attachment.html>


More information about the Gnutls-devel mailing list