Vulnerability Bulletins

DSA-3408 gnutls26 - security update

   
Affected software Debian
 
It was discovered that GnuTLS, a library implementing the TLS and SSLprotocols, incorrectly validates the first byte of padding in CBC modes.A remote attacker can possibly take advantage of this flaw to perform apadding oracle attack.

More info:

https://www.debian.org/security/2015/dsa-3408