On 2008-11-11 Michael Biebl <[EMAIL PROTECTED]> wrote:
[...]
> I think the backtrace led me in the correct direction, as it was
> segfaulting in libgnutls. I checked when libgnutls was last updated, and
> it was yesterday.
> I checked the changelog:

> gnutls26 (2.4.2-2) unstable; urgency=medium

>   * [CVE-2008-4989.diff] Fix man in the middle attack for certificate
>     verification. CVE-2008-4989 GNUTLS-SA-2008-3

>  -- Andreas Metzler <[EMAIL PROTECTED]>  Mon, 10 Nov 2008 19:42:54 +0100

> And indeed, this is the culprit. If I revert to version 2.4.2-1, the
> crashes in subversion are gone.

> I don't know the code, so I'm not sure if this is a bug in subversion or
> gnutls, so If CCed Andreas, maybe he can comment on this and if this bug
> should be reassigned to gnutls.

Is there a self-signed certificate involved? If yes this is probably a
duplicate of 505242.

A backtrace with libgnutls26-dbg will probably show it clearer.
cu andreas
-- 
`What a good friend you are to him, Dr. Maturin. His other friends are
so grateful to you.'
`I sew his ears on from time to time, sure'



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to