apache2-mod_gnutls

Edit Package apache2-mod_gnutls
No description set
Refresh
Refresh
Source Files
Filename Size Changed
README.invis 0000000358 358 Bytes
apache2-mod_gnutls-no-error-deprecated-declarations.patch 0000000332 332 Bytes
apache2-mod_gnutls.changes 0000014777 14.4 KB
apache2-mod_gnutls.spec 0000003784 3.7 KB
mod_gnutls-0.12.1.tar.bz2 0000454861 444 KB
mod_gnutls.conf 0000001263 1.23 KB
mod_gnutls.html 0000034424 33.6 KB
test-server.crt 0000001892 1.85 KB
test-server.key 0000001675 1.64 KB
Latest Revision
Petr Gajdos's avatar Petr Gajdos (pgajdos) committed (revision 20)
- version update to 0.12.1
  - Security fix: Remove an infinite loop in blocking read on transport
    timeout. Mod_gnutls versions from 0.9.0 to 0.12.0 (including) did
    not properly fail blocking read operations on TLS connections when
    the transport hit timeouts. Instead it entered an endless loop
    retrying the read operation, consuming CPU resources. This could be
    exploited for denial of service attacks. If trace level logging was
    enabled, it would also produce an excessive amount of log output
    during the loop, consuming disk space.
  - Replace obsolete Autoconf macros. Generating ./configure now
    requires Autoconf 2.69 (present in Debian Bullseye).
Comments 0
openSUSE Build Service is sponsored by