-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 20 Jan 2024 07:56:15 +0100 Source: gnutls28 Binary: gnutls-bin gnutls-bin-dbgsym guile-gnutls guile-gnutls-dbgsym libgnutls-dane0 libgnutls-dane0-dbgsym libgnutls-openssl27 libgnutls-openssl27-dbgsym libgnutls28-dev libgnutls30 libgnutls30-dbgsym libgnutlsxx28 libgnutlsxx28-dbgsym Architecture: armhf Version: 3.7.1-5+deb11u5 Distribution: bullseye Urgency: medium Maintainer: arm Build Daemon (arm-arm-01) Changed-By: Andreas Metzler Description: gnutls-bin - GNU TLS library - commandline utilities guile-gnutls - GNU TLS library - GNU Guile bindings libgnutls-dane0 - GNU TLS library - DANE security support libgnutls-openssl27 - GNU TLS library - OpenSSL wrapper libgnutls28-dev - GNU TLS library - development files libgnutls30 - GNU TLS library - main runtime library libgnutlsxx28 - GNU TLS library - C++ runtime library Closes: 1061045 1061046 Changes: gnutls28 (3.7.1-5+deb11u5) bullseye; urgency=medium . * Cherrypick two CVE fixes from 3.8.3: Fix assertion failure when verifying a certificate chain with a cycle of cross signatures. CVE-2024-0567 GNUTLS-SA-2024-01-09 Closes: #1061045 Fix more timing side-channel inside RSA-PSK key exchange. CVE-2024-0553 GNUTLS-SA-2024-01-14 Closes: #1061046 Checksums-Sha1: 069bc623f7fabae135bc61a7c9322b1ebbb10b68 878000 gnutls-bin-dbgsym_3.7.1-5+deb11u5_armhf.deb d740888aa1ad98351f78a3c9104aa579ecc6c551 618460 gnutls-bin_3.7.1-5+deb11u5_armhf.deb ce2622689cfa584bc12b285d6b0ff7636b0aa431 10961 gnutls28_3.7.1-5+deb11u5_armhf-buildd.buildinfo f8fcff7706ba6cb1b6a63770cf3646933c301606 224852 guile-gnutls-dbgsym_3.7.1-5+deb11u5_armhf.deb d076491826fbae218ba96454dc36edb59731dbb1 443812 guile-gnutls_3.7.1-5+deb11u5_armhf.deb 813571a6e22a8bce3ab88007d4b68700eaa9d218 64184 libgnutls-dane0-dbgsym_3.7.1-5+deb11u5_armhf.deb 6f170053a823d774e6b79704d97f216f110108bc 391108 libgnutls-dane0_3.7.1-5+deb11u5_armhf.deb 69eb00e7fdf6a170b9b4a689084c6b975bfba70d 65124 libgnutls-openssl27-dbgsym_3.7.1-5+deb11u5_armhf.deb f836fd34ddc9177016986e1cde937b75bba95f4e 390880 libgnutls-openssl27_3.7.1-5+deb11u5_armhf.deb 38cd60c931e96f6cc7b276263ce5533b585d9fd0 1260948 libgnutls28-dev_3.7.1-5+deb11u5_armhf.deb cf1d25cdf9a869b2cb33b37208418e65dea89457 1873248 libgnutls30-dbgsym_3.7.1-5+deb11u5_armhf.deb 11ddd64486d21998c70ac3562b3dd1650fc3655e 1280196 libgnutls30_3.7.1-5+deb11u5_armhf.deb 36bfe21e8803f4d243a074f79941c43d4fea3f25 51024 libgnutlsxx28-dbgsym_3.7.1-5+deb11u5_armhf.deb 3967e26e42e7c04ddce5c89f2df6d27bad8d7417 12232 libgnutlsxx28_3.7.1-5+deb11u5_armhf.deb Checksums-Sha256: 462a4358fd06cc00fb34961c7f9c9f7c86d49eb69e9b585930a917a90c206b76 878000 gnutls-bin-dbgsym_3.7.1-5+deb11u5_armhf.deb 85dae2b7ddb181f3860905d9790881bb20dfd924507beb9eeb708058b8819e7f 618460 gnutls-bin_3.7.1-5+deb11u5_armhf.deb 16397c634fbb928fc6e7804d6d0bbbdced8dcf79bcd565a0ad8c70510794234e 10961 gnutls28_3.7.1-5+deb11u5_armhf-buildd.buildinfo 8378d6934cf569be7b0b8e2d18e597cf1a5f8138a7df63baac7324af47b24c4e 224852 guile-gnutls-dbgsym_3.7.1-5+deb11u5_armhf.deb 8259cb5609d81612e4c359fb9ea00a6e288ede951efc2578718127d922c6ec59 443812 guile-gnutls_3.7.1-5+deb11u5_armhf.deb e8fb032574b859521287facf3fe0d5edfb545f3b2ee27ac8c3e9bf3be88f11a3 64184 libgnutls-dane0-dbgsym_3.7.1-5+deb11u5_armhf.deb ae96cec47b063eb35817ab1e8ed56ab06e9eede72390f78141b113d6fc65d8ee 391108 libgnutls-dane0_3.7.1-5+deb11u5_armhf.deb c10cd0bd181ef2ce1787f6f7421b94dc0c9509f38745b04fded86fe15fba30f5 65124 libgnutls-openssl27-dbgsym_3.7.1-5+deb11u5_armhf.deb 8537783766c8f912e7e3fb263003015de5f9712e7ed65efe18b3470318caf737 390880 libgnutls-openssl27_3.7.1-5+deb11u5_armhf.deb b4d7e6723830e97d0b883f82c18a3146bc02a86e338bef38ad7fa5fcf9fc5928 1260948 libgnutls28-dev_3.7.1-5+deb11u5_armhf.deb 1e18eafa27e0b660f596b65eb51c9aceb4a6c5a03b7dc642b9b476a14048ebeb 1873248 libgnutls30-dbgsym_3.7.1-5+deb11u5_armhf.deb bda8ac912431af9a59d5218279bb13bbc0dbcef2baa001de539cb7fd79df8d9b 1280196 libgnutls30_3.7.1-5+deb11u5_armhf.deb 90c674ac28048d7daa7deb4f364fce5279ea3ac514f26188f241dea5fa9c5779 51024 libgnutlsxx28-dbgsym_3.7.1-5+deb11u5_armhf.deb 0c55e33f854a10fa6ea8db42880559060d12bff1cf914a9a97ced12e319aff1c 12232 libgnutlsxx28_3.7.1-5+deb11u5_armhf.deb Files: e19576ba62325d9ee813e4c292e3d38d 878000 debug optional gnutls-bin-dbgsym_3.7.1-5+deb11u5_armhf.deb db258e7927e31a628d5fd6ff8bd5cc4e 618460 net optional gnutls-bin_3.7.1-5+deb11u5_armhf.deb 59794f86ae36f99c5fcba76636caff4f 10961 libs optional gnutls28_3.7.1-5+deb11u5_armhf-buildd.buildinfo 5b3f1f75769a040bb6a9efcb1022c522 224852 debug optional guile-gnutls-dbgsym_3.7.1-5+deb11u5_armhf.deb 907d264e8060107f83322b44277f26cb 443812 lisp optional guile-gnutls_3.7.1-5+deb11u5_armhf.deb bf32ab788785b41ce613cd254da9d84b 64184 debug optional libgnutls-dane0-dbgsym_3.7.1-5+deb11u5_armhf.deb 88e07bffb39c01e1c93b1ea5f81eea4e 391108 libs optional libgnutls-dane0_3.7.1-5+deb11u5_armhf.deb eb32be706aaa58b219d1bbeff0f05818 65124 debug optional libgnutls-openssl27-dbgsym_3.7.1-5+deb11u5_armhf.deb ce8e312fb53db3a96f1debe24f451f5f 390880 libs optional libgnutls-openssl27_3.7.1-5+deb11u5_armhf.deb 2def7b150d1de58046b5b8c7917ca620 1260948 libdevel optional libgnutls28-dev_3.7.1-5+deb11u5_armhf.deb 1241ef23923c0d95820a4d83227e4eb9 1873248 debug optional libgnutls30-dbgsym_3.7.1-5+deb11u5_armhf.deb 3fea3809be5745a70ac1f325dd63e9d2 1280196 libs optional libgnutls30_3.7.1-5+deb11u5_armhf.deb 1cb192f1b1ed4afb4ebb470207d1dc56 51024 debug optional libgnutlsxx28-dbgsym_3.7.1-5+deb11u5_armhf.deb 8aa33af0a1fadebcc6a75ad3111c0d1c 12232 libs optional libgnutlsxx28_3.7.1-5+deb11u5_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE4Prg5L5o4koxD5sKbi61NfD5HDwFAmYMdBEACgkQbi61NfD5 HDzaTBAAqcp0LGt4aBmGgDO04jemRvb28ChcNwb0YGlAkKyvhFDGJRk65UDl7yrh ujatq5E6G7Gb++uW8vD42AfVFcJe+2YV/33Z1Kd50BJWW6cEzhw4V1JIVBLvodlD E0trhK2S4azUXO4/HsfYvvJ14twS9D16iM6YBYiZXGSXf/KTjk/vnJFPen+aadBz 5A0eMkYNUiK+kfs0ZcxFa3fEMLHLp9R087i094ZaPMrwNZXEoeyE8hk10z9B8lqg r3cSykzaQrA/h64XT/Y1L6/QXw/O3wHEXsLUo9ABRmUVL3wfIabEtdKkbH1ExmUf 0vu7VR5BT0igK7/8lRXef284gZ1o1VfxfRNjNNAvYTDnFItPJhLNLHJEhZ1/ceNO QSGank1QbITMAj0DMc2Z9KfYRAyejGb4bpAYhcvp1h1pCA9R7z94t5XwyPF8GCXH oOJdQBDPXE7AW+vVGlht8MwT87Lfj6HgRkN4+SqCH5NCrdXlNshNf0Cn3t0k1Hun K4l7jKlTbyPygh07a0oTq/3Ye12iWWnCpITxp4E4T7Sri0s/0GtkrYunzwFsl0TV 8cOGlYlzSEBIKQX9LVv75FG6v1qTMC46JbYMPcs7F4U1gILeskbkcQIdggmUtqbY J4qL5DhRJ8HDdTo+HKqmDP92wHciRMLptzj/VlT17z4siCG1uBU= =NM+d -----END PGP SIGNATURE-----