-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 20 Jan 2024 07:56:15 +0100 Source: gnutls28 Binary: gnutls-bin gnutls-bin-dbgsym guile-gnutls guile-gnutls-dbgsym libgnutls-dane0 libgnutls-dane0-dbgsym libgnutls-openssl27 libgnutls-openssl27-dbgsym libgnutls28-dev libgnutls30 libgnutls30-dbgsym libgnutlsxx28 libgnutlsxx28-dbgsym Architecture: armel Version: 3.7.1-5+deb11u5 Distribution: bullseye Urgency: medium Maintainer: arm Build Daemon (arm-arm-04) Changed-By: Andreas Metzler Description: gnutls-bin - GNU TLS library - commandline utilities guile-gnutls - GNU TLS library - GNU Guile bindings libgnutls-dane0 - GNU TLS library - DANE security support libgnutls-openssl27 - GNU TLS library - OpenSSL wrapper libgnutls28-dev - GNU TLS library - development files libgnutls30 - GNU TLS library - main runtime library libgnutlsxx28 - GNU TLS library - C++ runtime library Closes: 1061045 1061046 Changes: gnutls28 (3.7.1-5+deb11u5) bullseye; urgency=medium . * Cherrypick two CVE fixes from 3.8.3: Fix assertion failure when verifying a certificate chain with a cycle of cross signatures. CVE-2024-0567 GNUTLS-SA-2024-01-09 Closes: #1061045 Fix more timing side-channel inside RSA-PSK key exchange. CVE-2024-0553 GNUTLS-SA-2024-01-14 Closes: #1061046 Checksums-Sha1: 6df29b864703ca05e03d7b82b65096ebcd068be5 859004 gnutls-bin-dbgsym_3.7.1-5+deb11u5_armel.deb 2ebb02c3a3d0452f4270d7c1d25b1bf62ec723ea 611868 gnutls-bin_3.7.1-5+deb11u5_armel.deb 33f23185183db79963a7c94f8896284f50cf2109 10959 gnutls28_3.7.1-5+deb11u5_armel-buildd.buildinfo 4845e20b1af22c2bd0da3d446c4e68f4a2f4fa05 227996 guile-gnutls-dbgsym_3.7.1-5+deb11u5_armel.deb b4a27e60a7b170cfa7d7b65b797ef19a233f7c8c 446048 guile-gnutls_3.7.1-5+deb11u5_armel.deb 046b0c8ef6722a8b8bc2a8b04b3c3ff174ad12ad 64172 libgnutls-dane0-dbgsym_3.7.1-5+deb11u5_armel.deb f7b7b7bea0a9a7616daa3ab2f2b82a4aa8e19f1a 393120 libgnutls-dane0_3.7.1-5+deb11u5_armel.deb 40f089e1757a52f14c5000775413fa939268711c 65332 libgnutls-openssl27-dbgsym_3.7.1-5+deb11u5_armel.deb 7f7592ebcd094ac0687cadb5e9e291bccd6553c3 392968 libgnutls-openssl27_3.7.1-5+deb11u5_armel.deb bd42797fd8adc77b7ca66095ce6befb24c937261 1248632 libgnutls28-dev_3.7.1-5+deb11u5_armel.deb 7c972c6052ec8cb8546380ee94149d0b82e87a51 1833460 libgnutls30-dbgsym_3.7.1-5+deb11u5_armel.deb 171f5a4035af40ed400f678cd92f3a9680df7327 1266012 libgnutls30_3.7.1-5+deb11u5_armel.deb c9233efc6909ba52e386a668a0f4c928820b28a3 50124 libgnutlsxx28-dbgsym_3.7.1-5+deb11u5_armel.deb dcfaccaadfe694a219c5961b6d5c9e5d188bf80a 12052 libgnutlsxx28_3.7.1-5+deb11u5_armel.deb Checksums-Sha256: dfa78c577e365361512e294c6815d2942cfa05139249526cc495d00528ef1f38 859004 gnutls-bin-dbgsym_3.7.1-5+deb11u5_armel.deb e732c610e93e8404db96e4f33047d4f33fbe6f220558727d93b2281a835efdfc 611868 gnutls-bin_3.7.1-5+deb11u5_armel.deb 63fbe1c0c8e082564b6bb864d27592dd34c78d60012dc9b9cfd058af8e1520bf 10959 gnutls28_3.7.1-5+deb11u5_armel-buildd.buildinfo f3f1436b86b373c03deb31d5570d3f1347e83fe981f31e5235e222d512381d61 227996 guile-gnutls-dbgsym_3.7.1-5+deb11u5_armel.deb 3d6381e8324830153bdf673a39232b9a14cc1bb2abf13ce0217237e0d9fcb85d 446048 guile-gnutls_3.7.1-5+deb11u5_armel.deb 209ef86a63a8f28595bc59514872775f5841b36bf50b7f7b29ddcff6947a9a70 64172 libgnutls-dane0-dbgsym_3.7.1-5+deb11u5_armel.deb d221ae3548cba8bb4017d646f0afe68bb5220b8dcef12fa728a2f2cdb6dc36c2 393120 libgnutls-dane0_3.7.1-5+deb11u5_armel.deb 24a342bc0fcd648bb29625af5da75722598012d4fbe9d87faf4b4975679af5bf 65332 libgnutls-openssl27-dbgsym_3.7.1-5+deb11u5_armel.deb 938ca59ef3b2c5d0ad8abff848012b7bc5927f46d8b700fa5d3ba50f9f30448c 392968 libgnutls-openssl27_3.7.1-5+deb11u5_armel.deb 5b0d493c8faf3ebfd109a160b440a816bc985764c6af95dc89031141614f5f17 1248632 libgnutls28-dev_3.7.1-5+deb11u5_armel.deb d5f0e1767bd29c92cbef4eb9b62391310dd7840985c6d122446f719abc88e05c 1833460 libgnutls30-dbgsym_3.7.1-5+deb11u5_armel.deb 21471124e12f3c2e61b00bb0a423bc9cadc64ec066bdb5b0cde0aae002413b22 1266012 libgnutls30_3.7.1-5+deb11u5_armel.deb 1849e632f02f10e16c6327e8927fa6bf7dc198d8bf0623bc529c23a6348b84e3 50124 libgnutlsxx28-dbgsym_3.7.1-5+deb11u5_armel.deb 726c5b3f4e20d5347d1722c7ddc79e18a57315e9638a21fd035e7ce0e7515a89 12052 libgnutlsxx28_3.7.1-5+deb11u5_armel.deb Files: 5de2a98ef577c11d4fa91fcde185d2fd 859004 debug optional gnutls-bin-dbgsym_3.7.1-5+deb11u5_armel.deb 54bb8ca24fb4ba243ee54020f546c8ed 611868 net optional gnutls-bin_3.7.1-5+deb11u5_armel.deb 95cc2783d107c32d5dd79d8a3f910593 10959 libs optional gnutls28_3.7.1-5+deb11u5_armel-buildd.buildinfo dc352565aea696d82a9c30ace30059f3 227996 debug optional guile-gnutls-dbgsym_3.7.1-5+deb11u5_armel.deb 977378a083b719111a468f4294c34fd6 446048 lisp optional guile-gnutls_3.7.1-5+deb11u5_armel.deb a048a49e0a268e817dd87ab6c2150b0d 64172 debug optional libgnutls-dane0-dbgsym_3.7.1-5+deb11u5_armel.deb 530cc352e4fd130b5064d2434fe259d0 393120 libs optional libgnutls-dane0_3.7.1-5+deb11u5_armel.deb 939ac790b8d9d8432dc66703de63855d 65332 debug optional libgnutls-openssl27-dbgsym_3.7.1-5+deb11u5_armel.deb 52a49f82d0a8c85fc1bc05a173855700 392968 libs optional libgnutls-openssl27_3.7.1-5+deb11u5_armel.deb 1c6f39c7518df45df4ed171d3e7e3293 1248632 libdevel optional libgnutls28-dev_3.7.1-5+deb11u5_armel.deb 7ad5a748efd98670e630554cfe67314d 1833460 debug optional libgnutls30-dbgsym_3.7.1-5+deb11u5_armel.deb 09cbfe11d41784c6d9cf316023fbe849 1266012 libs optional libgnutls30_3.7.1-5+deb11u5_armel.deb 1052e07f9b310de634398d19625f53ad 50124 debug optional libgnutlsxx28-dbgsym_3.7.1-5+deb11u5_armel.deb f3a4a3b1cfd71c70597870ab0855ad4d 12052 libs optional libgnutlsxx28_3.7.1-5+deb11u5_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmUDOxnfDwdc47jJKqoc2e3yvTA0FAmYMdL4ACgkQqoc2e3yv TA27Dg//b63Zy3bdYH+KdCm1xoU6PTFoN0ejzMuHbUGvXO4y8aNfkaVAhOWDENtt wGwa0anyeOTcxJRBT+fOWbFW9NIBJZsEUBrydhTIQZz9WXXjseTe+mKftGLX+Gpc 5K6WZI5PXa4CVmD2A5imZts8mz2/eet6ckVuKErk13GEmmkLUsYkyk3GEkGtlRpm ZF9BPISciauDAXeISdH/KAVgAFFW7bnaNVmkZlVyzywJ6N+29JhsMj/OGaHETtdO /d22EA0DkxHalwadKRNK+zWY/5HJLTZ8ULQIcSWuooxCTPa6JzCYaDIYfedugwar 2c3c0l24t2NldS0/0WQC7Ldld1gPeEyIdwPi3/yBP9ldGL2KbAiZtGUJLKvB7hBO F3WsyhXhKPcNGQ5IrRTr3v3SDeqaxPlnSRL/fan+CHfwOthXXOxhHJQ6iubQUSfE EjTVHwwOqEDqckb6abhhrUBwOBwAK6CVwZSQ0GM6NseoiJ/jI2KNSgFeqr0K98UI Elu9Dlz2kgOOxBY7zy837t74BHmCiU/wbPLBayIp6kb2wBGHGYYX9EqHJXKetsg7 3IN0Qnwz7x0AYkuqlnayyymY0rhQgYQHvma4jS5n90yRTjrFbGUNKmUUuLtRo/XW SkPxXHNERtNND4iXgySaNq1AiB3caGdXsGLewjbkQs1Jws5cPdc= =scRY -----END PGP SIGNATURE-----