USN-2127-1: GnuTLS vulnerability
4 March 2014
Fraudulent security certificates could allow sensitive information to be exposed when accessing the Internet.
- gnutls26 - GNU TLS library
Nikos Mavrogiannopoulos discovered that GnuTLS incorrectly handled
certificate verification functions. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited with
specially crafted certificates to view sensitive information.
The problem can be corrected by updating your system to the following package versions:
In general, a standard system update will make all the necessary changes.