package/gnutls: security bump to 3.6.14
authorStefan Sørensen <stefan.sorensen@spectralink.com>
Thu, 11 Jun 2020 05:31:51 +0000 (07:31 +0200)
committerYann E. MORIN <yann.morin.1998@free.fr>
Sun, 21 Jun 2020 21:32:43 +0000 (23:32 +0200)
commit16ea3ee784c5203b33c086f84474b1dba6a3e54a
treeed2476a5eb0979534953a9022227f8e68ad5d46d
parent7d2ca71d60ab7a6704c06bef5fee82862b1ea620
package/gnutls: security bump to 3.6.14

Fixes the following security issue:

 * CVE-2020-13777: It was found that GnuTLS 3.6.4 introduced a
   regression in the TLS protocol implementation. This caused the TLS
   server to not securely construct a session ticket encryption key
   considering the application supplied secret, allowing a MitM
   attacker to bypass authentication in TLS 1.3 and recover previous
   conversations in TLS 1.2

Release announcement:
 https://lists.gnupg.org/pipermail/gnutls-help/2020-June/004648.html

Signed-off-by: Stefan Sørensen <stefan.sorensen@spectralink.com>
[yann.morin.1998@free.fr: two spaces in hash file]
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
package/gnutls/gnutls.hash
package/gnutls/gnutls.mk