tcl-tls 1.6 is out of date and therefore many site refuse to connect (heartbleed)

Bug #1464919 reported by Holger
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
tcltls (Ubuntu)
Fix Released
Critical
Unassigned
Nominated for Vivid by Alberto Salvia Novella

Bug Description

The current version is https://sourceforge.net/projects/tls/files/tls/1.6.4/, and only this version is capable of connecting to computers which refuse to use old ciphers and methods like SSLv2, SSLv3, and TLS 1.0. For instance imap.strato.de only accepts non-broken ciphers and refuses connections with version 1.6.

Additionally, this old version will also allow for insecure connections.

Therefore, an update is crucial in order to maintain connectivity for at least 14.4 LTS and 15.4.

ProblemType: Bug
DistroRelease: Ubuntu 15.04
Package: tcl-tls 1.6+dfsg-3
ProcVersionSignature: Ubuntu 3.19.0-20.20-generic 3.19.8
Uname: Linux 3.19.0-20-generic x86_64
ApportVersion: 2.17.2-0ubuntu1.1
Architecture: amd64
CurrentDesktop: Unity
Date: Sat Jun 13 22:48:08 2015
InstallationDate: Installed on 2015-02-16 (117 days ago)
InstallationMedia: Ubuntu 14.10 "Utopic Unicorn" - Release amd64 (20141022.1)
ProcEnviron:
 LANGUAGE=de_DE
 PATH=(custom, no user)
 XDG_RUNTIME_DIR=<set>
 LANG=de_DE.UTF-8
 SHELL=/bin/bash
SourcePackage: tcltls
UpgradeStatus: Upgraded to vivid on 2015-05-11 (32 days ago)

Revision history for this message
Holger (holger-jakobs) wrote :
Revision history for this message
Seth Arnold (seth-arnold) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures

Note that we don't do wholesale version updates in security updates, but rather include specific patches that fix specific problems, see https://wiki.ubuntu.com/SecurityTeam/FAQ#Versions for more information. Thanks.

information type: Private Security → Public Security
tags: added: poodle weakdh
Changed in tcltls (Ubuntu):
status: New → Confirmed
Changed in tcltls (Ubuntu):
importance: Undecided → Critical
Changed in tcltls (Ubuntu):
status: Confirmed → Triaged
Revision history for this message
Holger (holger-jakobs) wrote :

A very similar problem has occurred again, because Ubuntu refuses to update depending packages simultaneously with OpenSSL updates. Since July tcltls is non-functional, because there has been no update even in 15.10 to version 1.6.7 of tcltls.

Revision history for this message
Mattia Rizzolo (mapreri) wrote :

1.6.7 is in xenial, thus closing.

Changed in tcltls (Ubuntu):
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.