Change logs for gnutls26 source package in Vivid

  • gnutls26 (2.12.23-18ubuntu1) vivid; urgency=medium
    
      * Merge with Debian; remaining changes:
        - Link test-lock and test-thread_create with -Wl,--no-as-needed; see
          https://lists.gnu.org/archive/html/bug-gnulib/2013-10/msg00017.html.
        - debian/rules: Set CC on cross-builds, so autoconf doesn't lose its mind.
    
      * Dropped changes:
        - restore sipsak Breaks, ours is now new enough to deal with this.
        - drop CVE-2014-3466 security upload, included in debian.
        - debian/patches/99_update-libtool.patch: Debian uses autoreconf.
    
    gnutls26 (2.12.23-18) experimental; urgency=medium
    
      * 32_fix-gcrypt-private-api-usage.patch from gpg4win: Allow building
        against libgcrypt20. (Thanks, Werner Koch for the pointer.)
      * (Build-)depend on libgcrypt20-dev.
    
    gnutls26 (2.12.23-17) unstable; urgency=medium
    
      [ Mauricio Faria de Oliveira ]
      * Add fixes for automake (30_fix_automake_oldies.patch).
      * Run dh-autoreconf on build. (Closes: #751796)
    
      [ Andreas Metzler ]
      * 31_linkage-gpgerror.diff: Stop unnecessary linkage against libgpg-error
        caused by buildung with up to date lib-link.m4.
    
    gnutls26 (2.12.23-16) unstable; urgency=high
    
      * Drop libgnutls26-dbg Conflicts with libgnutls13-dbg, libgnutls28-dbg.
        These have been unnecessary since we started using dh compat v9, where
        debugging symbols are installed to /usr/lib/debug/.build-id.
      * 29_Prevent-memory-corruption.diff from upstream GIT. Fix memory corruption
        on client side caused by specifically crafted ServerHello.
        GNUTLS-SA-2014-3 / CVE-2014-3466
     -- Adam Conrad <email address hidden>   Fri, 27 Mar 2015 07:07:15 -0600
  • gnutls26 (2.12.23-15ubuntu2) utopic; urgency=medium
    
      * SECURITY UPDATE: memory corruption due to server hello parsing
        - debian/patches/CVE-2014-3466.patch: validate session_id_len in
          lib/gnutls_handshake.c.
        - CVE-2014-3466
     -- Marc Deslauriers <email address hidden>   Sun, 01 Jun 2014 11:02:11 -0400