upgrade to 1.0.20; Mr. Hornik has discovered error in X.509 certificate chain verification procedure in GnuTLS library. The certificate chain should be verified from last root certificate to the first certificate. Otherwise a lot of unauthorized CPU processing can be forced to check certificate signatures signed with arbitrary RSA/DSA keys chosen by attacker.; ok maintainer
5 lines
169 B
Plaintext
5 lines
169 B
Plaintext
@comment $OpenBSD: PFRAG.shared,v 1.4 2004/09/22 08:06:40 robert Exp $
|
|
@lib lib/libgnutls-extra.so.12.20
|
|
@lib lib/libgnutls-openssl.so.12.20
|
|
@lib lib/libgnutls.so.12.20
|