diff --git a/SPECS/gnutls.spec b/SPECS/gnutls.spec index 3a28df8..9ec2d80 100644 --- a/SPECS/gnutls.spec +++ b/SPECS/gnutls.spec @@ -1,21 +1,14 @@ -Version: 3.6.8 -Release: 11%{?dist} +Version: 3.6.14 +Release: 6%{?dist} Patch1: gnutls-3.2.7-rpath.patch Patch2: gnutls-3.6.4-no-now-guile.patch -Patch3: gnutls-3.6.5-fix-fips-signature-post.patch -Patch4: gnutls-3.6.8-fips-aes-cbc-kat.patch -Patch5: gnutls-3.6.8-multiple-key-updates.patch -Patch6: gnutls-3.6.8-fips-rng-continuous.patch -Patch7: gnutls-3.6.8-session-ticket-ub.patch -Patch8: gnutls-3.6.8-pkcs11-login-error.patch -Patch9: gnutls-3.6.8-fips-deterministic-ecdsa.patch -Patch10: gnutls-3.6.8-aead-cipher-encryptv2.patch -Patch11: gnutls-3.6.8-fips-rsa-random-selftests.patch -Patch12: gnutls-3.6.8-decr-len.patch -Patch13: gnutls-3.6.8-fix-aead-cipher-encryptv2.patch -Patch14: gnutls-3.6.8-fix-cfb8-decrypt.patch -Patch15: gnutls-3.6.12-dtls-random.patch -Patch16: gnutls-3.6.14-totp-init.patch +Patch3: gnutls-3.6.13-enable-intel-cet.patch +Patch4: gnutls-3.6.14-autogen-int.patch +Patch5: gnutls-3.6.14-fips-mode-check.patch +Patch6: gnutls-3.6.14-fips-dh-primes.patch +Patch7: gnutls-3.6.14-memcmp.patch +Patch8: gnutls-3.6.14-fips-dh-check.patch +Patch9: gnutls-3.6.14-fix-iovec-memory-leak.patch %bcond_without dane %if 0%{?rhel} %bcond_with guile @@ -61,7 +54,7 @@ BuildRequires: guile-devel URL: http://www.gnutls.org/ Source0: ftp://ftp.gnutls.org/gcrypt/gnutls/v3.6/%{name}-%{version}.tar.xz Source1: ftp://ftp.gnutls.org/gcrypt/gnutls/v3.6/%{name}-%{version}.tar.xz.sig -Source2: gpgkey-1F42418905D8206AA754CCDC29EE58B996865171.gpg +Source2: gpgkey-462225C3B46F34879FC8496CD605848ED7E69871.gpg # Wildcard bundling exception https://fedorahosted.org/fpc/ticket/174 Provides: bundled(gnulib) = 20130424 @@ -299,11 +292,35 @@ fi %endif %changelog -* Mon Jun 8 2020 Daiki Ueno - 3.6.8-11 -- Fix CVE-2020-13777 (#1844147) +* Mon Aug 24 2020 Daiki Ueno - 3.6.14-6 +- Fix memory leak when serializing iovec_t (#1844112) + +* Sat Jul 18 2020 Daiki Ueno - 3.6.14-5 +- Perform validation checks on (EC)DH public keys and share secrets (#1855803) + +* Mon Jun 29 2020 Daiki Ueno - 3.6.14-4 +- Tighten FIPS DH primes check according to SP800-56A (rev 3) (#1849079) + +* Fri Jun 5 2020 Daiki Ueno - 3.6.14-3 +- Update gnutls-3.6.14-fips-mode-check.patch + +* Thu Jun 4 2020 Daiki Ueno - 3.6.14-2 +- Return false from gnutls_fips140_mode_enabled() if selftests failed (#1827687) + +* Thu Jun 4 2020 Daiki Ueno - 3.6.14-1 +- Update to upstream 3.6.14 release + +* Mon May 25 2020 Anderson Sasaki - 3.6.13-3 +- Add an option to gnutls-cli to wait for resumption under TLS 1.3 (#1677754) + +* Wed May 20 2020 Anderson Sasaki - 3.6.13-2 +- Enable Intel CET (#1838476) + +* Tue May 5 2020 Daiki Ueno - 3.6.13-1 +- Update to upstream 3.6.13 release * Tue Apr 21 2020 Daiki Ueno - 3.6.8-10 -- Fix CVE-2020-11501 (#1826176) +- Fix CVE-2020-11501 (#1822005) * Wed Nov 6 2019 Daiki Ueno - 3.6.8-9 - Fix CFB8 decryption when repeatedly called (#1757848)