Debian Package Tracker
Register | Log in
Subscribe

tlslite-ng

Choose email to subscribe with

general
  • source: tlslite-ng (main)
  • version: 0.7.5-2
  • maintainer: Daniel Stender (DMD)
  • uploaders: Debian Python Modules Team (archive) [DMD]
  • arch: all
  • std-ver: 4.2.1
  • VCS: Git (Browse)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 0.6.0-1+deb9u1
  • stable: 0.7.5-2
versioned links
  • 0.6.0-1+deb9u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.7.5-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python-tlslite-ng
  • python3-tlslite-ng
package is gone
This package is not in any development repository. This probably means that the package has been removed (or has been renamed). Thus the information here is of little interest ... the package is going to disappear unless someone takes it over and reintroduces it.
action needed
1 ignored security issue in stretch low
There is 1 open security issue in stretch.
1 issue skipped by the security teams:
  • CVE-2020-26263: tlslite-ng is an open source python library that implements SSL and TLS cryptographic protocols. In tlslite-ng before versions 0.7.6 and 0.8.0-alpha39, the code that performs decryption and padding check in RSA PKCS#1 v1.5 decryption is data dependant. In particular, the code has multiple ways in which it leaks information about the decrypted ciphertext. It aborts as soon as the plaintext doesn't start with 0x00, 0x02. All TLS servers that enable RSA key exchange as well as applications that use the RSA decryption API directly are vulnerable. This is patched in versions 0.7.6 and 0.8.0-alpha39. Note: the patches depend on Python processing the individual bytes in side-channel free manner, this is known to not the case (see reference). As such, users that require side-channel resistance are recommended to use different TLS implementations, as stated in the security policy of tlslite-ng.
Please fix it.
Created: 2020-12-21 Last update: 2021-01-07 13:05
1 ignored security issue in buster low
There is 1 open security issue in buster.
1 issue skipped by the security teams:
  • CVE-2020-26263: tlslite-ng is an open source python library that implements SSL and TLS cryptographic protocols. In tlslite-ng before versions 0.7.6 and 0.8.0-alpha39, the code that performs decryption and padding check in RSA PKCS#1 v1.5 decryption is data dependant. In particular, the code has multiple ways in which it leaks information about the decrypted ciphertext. It aborts as soon as the plaintext doesn't start with 0x00, 0x02. All TLS servers that enable RSA key exchange as well as applications that use the RSA decryption API directly are vulnerable. This is patched in versions 0.7.6 and 0.8.0-alpha39. Note: the patches depend on Python processing the individual bytes in side-channel free manner, this is known to not the case (see reference). As such, users that require side-channel resistance are recommended to use different TLS implementations, as stated in the security policy of tlslite-ng.
Please fix it.
Created: 2020-12-21 Last update: 2021-01-07 13:05
news
[rss feed]
  • [2019-08-13] tlslite-ng REMOVED from testing (Debian testing watch)
  • [2019-08-12] Removed 0.7.5-2 from unstable (Debian FTP Masters)
  • [2018-11-05] tlslite-ng 0.7.5-2 MIGRATED to testing (Debian testing watch)
  • [2018-11-02] Accepted tlslite-ng 0.7.5-2 (all source) into unstable (Daniel Stender)
  • [2018-08-03] tlslite-ng 0.7.5-1 MIGRATED to testing (Debian testing watch)
  • [2018-08-01] Accepted tlslite-ng 0.7.5-1 (source all) into unstable (Daniel Stender)
  • [2018-07-07] Accepted tlslite-ng 0.6.0-1+deb9u1 (source all) into proposed-updates->stable-new, proposed-updates (Daniel Stender)
  • [2018-04-21] tlslite-ng 0.7.4-1 MIGRATED to testing (Debian testing watch)
  • [2018-04-15] Accepted tlslite-ng 0.7.4-1 (source all) into unstable (Daniel Stender)
  • [2018-03-25] tlslite-ng 0.7.3-1 MIGRATED to testing (Debian testing watch)
  • [2018-03-19] Accepted tlslite-ng 0.7.3-1 (source all) into unstable (Daniel Stender)
  • [2018-03-17] tlslite-ng 0.7.1-1 MIGRATED to testing (Debian testing watch)
  • [2018-03-12] Accepted tlslite-ng 0.7.1-1 (source all) into unstable (Daniel Stender)
  • [2018-02-24] tlslite-ng 0.7.0-3 MIGRATED to testing (Debian testing watch)
  • [2018-02-18] Accepted tlslite-ng 0.7.0-3 (source all) into unstable (Daniel Stender)
  • [2017-08-14] tlslite-ng 0.7.0-2 MIGRATED to testing (Debian testing watch)
  • [2017-08-08] Accepted tlslite-ng 0.7.0-2 (source all) into unstable (Daniel Stender)
  • [2017-08-05] Accepted tlslite-ng 0.7.0-1 (source all) into unstable (Daniel Stender)
  • [2017-07-27] tlslite-ng 0.6.0-2 MIGRATED to testing (Debian testing watch)
  • [2017-07-23] Accepted tlslite-ng 0.6.0-2 (source all) into unstable (Daniel Stender)
  • [2016-11-22] tlslite-ng 0.6.0-1 MIGRATED to testing (Debian testing watch)
  • [2016-11-16] Accepted tlslite-ng 0.6.0-1 (source all) into unstable (Daniel Stender)
  • [2016-04-04] tlslite-ng 0.5.2-1 MIGRATED to testing (Debian testing watch)
  • [2016-03-29] Accepted tlslite-ng 0.5.2-1 (source all) into unstable (Daniel Stender)
  • [2016-02-14] tlslite-ng 0.5.1-1 MIGRATED to testing (Debian testing watch)
  • [2016-02-08] Accepted tlslite-ng 0.5.1-1 (source all) into unstable, unstable (Daniel Stender) (signed by: Gianfranco Costamagna)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • buildd: logs, clang
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debci

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing