From 99c7cafd7376277cb010e2b7de0bf40de7ee6282 Mon Sep 17 00:00:00 2001 From: Patrick J Volkerding Date: Tue, 31 Mar 2020 19:01:17 +0000 Subject: Tue Mar 31 19:01:17 UTC 2020 a/dialog-1.3_20200327-x86_64-1.txz: Upgraded. a/openssl-solibs-1.1.1f-x86_64-1.txz: Upgraded. ap/nano-4.9.1-x86_64-1.txz: Upgraded. l/elfutils-0.179-x86_64-1.txz: Upgraded. n/gnutls-3.6.13-x86_64-1.txz: Upgraded. This update fixes a security issue: libgnutls: Fix a DTLS-protocol regression (caused by TLS1.3 support), since 3.6.3. The DTLS client would not contribute any randomness to the DTLS negotiation, breaking the security guarantees of the DTLS protocol. [GNUTLS-SA-2020-03-31, CVSS: high] (* Security fix *) n/httpd-2.4.43-x86_64-1.txz: Upgraded. n/openssl-1.1.1f-x86_64-1.txz: Upgraded. --- ChangeLog.txt | 15 +++++++++++++++ 1 file changed, 15 insertions(+) (limited to 'ChangeLog.txt') diff --git a/ChangeLog.txt b/ChangeLog.txt index 683cc9c7..21718694 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -1,3 +1,18 @@ +Tue Mar 31 19:01:17 UTC 2020 +a/dialog-1.3_20200327-x86_64-1.txz: Upgraded. +a/openssl-solibs-1.1.1f-x86_64-1.txz: Upgraded. +ap/nano-4.9.1-x86_64-1.txz: Upgraded. +l/elfutils-0.179-x86_64-1.txz: Upgraded. +n/gnutls-3.6.13-x86_64-1.txz: Upgraded. + This update fixes a security issue: + libgnutls: Fix a DTLS-protocol regression (caused by TLS1.3 support), + since 3.6.3. The DTLS client would not contribute any randomness to the + DTLS negotiation, breaking the security guarantees of the DTLS protocol. + [GNUTLS-SA-2020-03-31, CVSS: high] + (* Security fix *) +n/httpd-2.4.43-x86_64-1.txz: Upgraded. +n/openssl-1.1.1f-x86_64-1.txz: Upgraded. ++--------------------------+ Tue Mar 31 04:00:43 UTC 2020 a/pkgtools-15.0-noarch-31.txz: Rebuilt. removepkg: support an uninstall script. See removepkg(8). -- cgit v1.2.3