-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 15 Jun 2024 13:22:35 +0200 Source: gnutls28 Binary: gnutls-bin gnutls-bin-dbgsym guile-gnutls guile-gnutls-dbgsym libgnutls-dane0 libgnutls-dane0-dbgsym libgnutls-openssl27 libgnutls-openssl27-dbgsym libgnutls28-dev libgnutls30 libgnutls30-dbgsym libgnutlsxx30 libgnutlsxx30-dbgsym Architecture: ppc64el Version: 3.7.9-2+deb12u3 Distribution: bookworm Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-osuosl-02) Changed-By: Andreas Metzler Description: gnutls-bin - GNU TLS library - commandline utilities guile-gnutls - GNU TLS library - GNU Guile bindings libgnutls-dane0 - GNU TLS library - DANE security support libgnutls-openssl27 - GNU TLS library - OpenSSL wrapper libgnutls28-dev - GNU TLS library - development files libgnutls30 - GNU TLS library - main runtime library libgnutlsxx30 - GNU TLS library - C++ runtime library Closes: 1067463 1067464 Changes: gnutls28 (3.7.9-2+deb12u3) bookworm; urgency=medium . * Update to 3.7.11: + Replace 60-auth-rsa_psk-side-step-potential-side-channel.patch 61-x509-detect-loop-in-certificate-chain.patch 62-rsa-psk-minimize-branching-after-decryption.patch with versions from gnutls_3_7_x branch instead of manual backports from 3.8.x. + Add 53-fips-fix-checking-on-hash-algorithm-used-in-ECDSA.patch (Fix checking on hash algorithm used in ECDSA in FIPS mode) and 54-fips-mark-composite-signature-API-not-approved.patch (Mark composite signature API non-approved in FIPS mode.) to allow straight cherry-picking of later patches. + 63_01-gnutls_x509_trust_list_verify_crt2-remove-length-lim.patch libgnutls: Fixed a bug where certtool crashed when verifying a certificate chain with more than 16 certificates. Reported by William Woodruff (#1525) and yixiangzhike (#1527). [GNUTLS-SA-2024-01-23, CVSS: medium] [CVE-2024-28835] Closes: #1067463 + 63_02-nettle-avoid-normalization-of-mpz_t-in-deterministic.patch libgnutls: Fix side-channel in the deterministic ECDSA. Reported by George Pantelakis (#1516). [GNUTLS-SA-2023-12-04, CVSS: medium] [CVE-2024-28834] Closes: #1067464 + 63_03-serv-fix-memleak-when-a-connected-client-disappears.patch Fix a memleak in gnutls-serv when a connected client disappears. + 63_04-lib-fix-a-segfault-in-_gnutls13_recv_end_of_early_da.patch Fix a segfault in _gnutls13_recv_end_of_early_data(). + 63_05-lib-fix-a-potential-segfault-in-_gnutls13_recv_finis.patch Fix a potential segfault in _gnutls13_recv_finished(). Checksums-Sha1: b391abbb2bbf0ace3ad2e643fbdd620f6e5a7e5c 856596 gnutls-bin-dbgsym_3.7.9-2+deb12u3_ppc64el.deb fbf897548ef4eccdafec3a34730df0d302369808 640504 gnutls-bin_3.7.9-2+deb12u3_ppc64el.deb a1992559eda33f5000bb958e757b9dfb517c4d90 11283 gnutls28_3.7.9-2+deb12u3_ppc64el-buildd.buildinfo 0cc5f95a56986d6f52b43611229f80c7de1001ac 267912 guile-gnutls-dbgsym_3.7.9-2+deb12u3_ppc64el.deb 250655303a63f5afbba8c256b80b654bd01d8795 463152 guile-gnutls_3.7.9-2+deb12u3_ppc64el.deb 7bd1fe557b42a7c56d9137b6a3e16e1aea54d99c 94708 libgnutls-dane0-dbgsym_3.7.9-2+deb12u3_ppc64el.deb d3dd9b5a8c6d3bb0bdc1b650ff4e67a0697f3574 409012 libgnutls-dane0_3.7.9-2+deb12u3_ppc64el.deb 0aa5f71630bb05148055659ee944127dd6f7b4dd 95800 libgnutls-openssl27-dbgsym_3.7.9-2+deb12u3_ppc64el.deb 8db7cb275f189f5111a9aaab02e26a124a96f780 408768 libgnutls-openssl27_3.7.9-2+deb12u3_ppc64el.deb 8b0a6557426a5f4f235f7d3eaa9d3cb6359d118a 1413084 libgnutls28-dev_3.7.9-2+deb12u3_ppc64el.deb fc637ed943addd08cc13d905c7d49cce6fa3e428 2056756 libgnutls30-dbgsym_3.7.9-2+deb12u3_ppc64el.deb 8e689183595bc92d3850f4cf2f1918e76c890858 1369948 libgnutls30_3.7.9-2+deb12u3_ppc64el.deb cc4ea569e3edb2049bd7d907c05a9064a2485d0e 49928 libgnutlsxx30-dbgsym_3.7.9-2+deb12u3_ppc64el.deb 767aaf0d2d16714a98784474dc53c858538ee0d6 14544 libgnutlsxx30_3.7.9-2+deb12u3_ppc64el.deb Checksums-Sha256: 15adf9ef0a574a1ef93668c2ee194fb0ddd971005ee27e1042b837a45eff3417 856596 gnutls-bin-dbgsym_3.7.9-2+deb12u3_ppc64el.deb fe00fb3d74675362b2304563030e72efe466aab9b1b3813c788ac36b168671a9 640504 gnutls-bin_3.7.9-2+deb12u3_ppc64el.deb 335a3a1c267475b92e5c30fac956d490a3ea844f8f31f06f9f7171ebf9c1ae18 11283 gnutls28_3.7.9-2+deb12u3_ppc64el-buildd.buildinfo 01434372cd761d87836e149c1e6d2876870ae8210e3d71a1aa458b5b5f46af5f 267912 guile-gnutls-dbgsym_3.7.9-2+deb12u3_ppc64el.deb 834bbc08c193c4f6bfb36933251ceff4c866f7722e5f6949cf0df520ed48e925 463152 guile-gnutls_3.7.9-2+deb12u3_ppc64el.deb eb0165bb61932f71c65633c7117719188c9a982806bb5d36db17e73ff8a51441 94708 libgnutls-dane0-dbgsym_3.7.9-2+deb12u3_ppc64el.deb 16b438c46618d92fe55607cc4aad9ee8e5a8b80ca28778921f905a05080cb77e 409012 libgnutls-dane0_3.7.9-2+deb12u3_ppc64el.deb cb0ef5138091ea9dc4ddef28479481465afed00bdb7f7c735502a7448708cbd7 95800 libgnutls-openssl27-dbgsym_3.7.9-2+deb12u3_ppc64el.deb 3e794ef9b45294718ce49bdea66470faded6b8dfdc084470da012be4fa435fe6 408768 libgnutls-openssl27_3.7.9-2+deb12u3_ppc64el.deb eca81f2ad4f4fdca471a8b76f2ab6a0d7764a1503083eaa69f1f0a781046eb4c 1413084 libgnutls28-dev_3.7.9-2+deb12u3_ppc64el.deb b57f10a718ada7c48ced07340e797d79dd2e52e07187c30a1d917c284d5b5f04 2056756 libgnutls30-dbgsym_3.7.9-2+deb12u3_ppc64el.deb c07917d98da5c1d73dd2f4b88683ff4e9eb8d7468a5bedbe8ab398812ad47ec9 1369948 libgnutls30_3.7.9-2+deb12u3_ppc64el.deb 4552980bacc30f0ca77dd9c693a3814a826941cac9574bf017065802e1ff837e 49928 libgnutlsxx30-dbgsym_3.7.9-2+deb12u3_ppc64el.deb 3985ccdf644e8d5c19a9c16403cdd3be2b4e2533ad843cfd29b9b7e99155a1d3 14544 libgnutlsxx30_3.7.9-2+deb12u3_ppc64el.deb Files: 9c03e4d9bd149ee02708dff2209891df 856596 debug optional gnutls-bin-dbgsym_3.7.9-2+deb12u3_ppc64el.deb afa02882286e2f12c6f101b2b9e07f8c 640504 net optional gnutls-bin_3.7.9-2+deb12u3_ppc64el.deb 8046f3b453353301d49d30f0741ace1b 11283 libs optional gnutls28_3.7.9-2+deb12u3_ppc64el-buildd.buildinfo b9410084fbbfb86a88a298f6e02be4e1 267912 debug optional guile-gnutls-dbgsym_3.7.9-2+deb12u3_ppc64el.deb 489581cf8d3049056cb7cf6034879e52 463152 lisp optional guile-gnutls_3.7.9-2+deb12u3_ppc64el.deb 108f34e8f451e2a1db6eabcfe9469122 94708 debug optional libgnutls-dane0-dbgsym_3.7.9-2+deb12u3_ppc64el.deb 83733afd9757b10d3b2765f810f3face 409012 libs optional libgnutls-dane0_3.7.9-2+deb12u3_ppc64el.deb d658a76055095ac595fc2f98bec81b9d 95800 debug optional libgnutls-openssl27-dbgsym_3.7.9-2+deb12u3_ppc64el.deb 3959162cf26f0c89cf6dc547cf363dcb 408768 libs optional libgnutls-openssl27_3.7.9-2+deb12u3_ppc64el.deb 9cb8d17312c65e36790d284d30ff6ad5 1413084 libdevel optional libgnutls28-dev_3.7.9-2+deb12u3_ppc64el.deb 8acd165711d74c0aeddf51ff6b23f6b8 2056756 debug optional libgnutls30-dbgsym_3.7.9-2+deb12u3_ppc64el.deb 1bbdf244a85e09ac2309335b13051c97 1369948 libs optional libgnutls30_3.7.9-2+deb12u3_ppc64el.deb 1089e1a6129019e516c308385e74a963 49928 debug optional libgnutlsxx30-dbgsym_3.7.9-2+deb12u3_ppc64el.deb 8ba09761a0661adc32e7f23300c3aeb4 14544 libs optional libgnutlsxx30_3.7.9-2+deb12u3_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0YcVZfZCWQv84jpRNcqbeolus3sFAmZvVT0ACgkQNcqbeolu s3vOsw//VKQ4+CYw4yfuhez3ZGDg4GHgDHZ92RebAKr9LhEDbgHj0I8LFfgqpCn2 9YeoFc+5Ex94wUIkRoNcJzG+/Fq1tEaP6Zd0UinKebAYh+I5Bf9gDjvbObZ2VJ89 7bjn6dZnEFPmz7lJn/UNgIczFjQWPAYrN+HsfwxSsatkC2aGOgZdmTLX/XvXoApO Qjg8sKJaAs56OLzQhME8+51s6mepBdHL0GfBNT8ZwngHTxHhQr1J+RkSTY3Yzf9Z fqSUy+/B9lI79WYToxKiq2qM4sNGwJvmii7+mtKF7OQcqLZWS5FoFtPYQobUcb7V RiPJkFByoIcOGpHNHvrDcqfQKx7oIkpEFrf9urXOJxhOf9f1Ce1saVxHSrjurLhy fx55bTYXwtUZ4kRCy6IA9mwHU7mOCGWgMNsMdYMMW+ImhtaDtUfBLC8D4AdsA6dl n91NQhQK5VxMkWN3YHSYWFI4GrBaR9yV1sGqHr72+qa/0YSspur94MGdC1Ug3BUX +5VvxJwm+6QX06Y2Xctn8gMYuYUineSgHwNePKuoolmVKoirEq0xI+IG2E1ChNYp slD6da4E6w7JyDPNJhshQW75DREE7exErRObpmL6CIe5p+i7GWIsYjNL56tRFuwr 857+l97OYnyV3/w5DNDzW7KRmKdRYXR/0C5RiEMmO8Bir9cAIpo= =zEoE -----END PGP SIGNATURE-----