-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 20 Jan 2024 07:56:15 +0100 Source: gnutls28 Binary: gnutls-bin gnutls-bin-dbgsym guile-gnutls guile-gnutls-dbgsym libgnutls-dane0 libgnutls-dane0-dbgsym libgnutls-openssl27 libgnutls-openssl27-dbgsym libgnutls28-dev libgnutls30 libgnutls30-dbgsym libgnutlsxx28 libgnutlsxx28-dbgsym Architecture: arm64 Version: 3.7.1-5+deb11u5 Distribution: bullseye Urgency: medium Maintainer: arm Build Daemon (arm-conova-04) Changed-By: Andreas Metzler Description: gnutls-bin - GNU TLS library - commandline utilities guile-gnutls - GNU TLS library - GNU Guile bindings libgnutls-dane0 - GNU TLS library - DANE security support libgnutls-openssl27 - GNU TLS library - OpenSSL wrapper libgnutls28-dev - GNU TLS library - development files libgnutls30 - GNU TLS library - main runtime library libgnutlsxx28 - GNU TLS library - C++ runtime library Closes: 1061045 1061046 Changes: gnutls28 (3.7.1-5+deb11u5) bullseye; urgency=medium . * Cherrypick two CVE fixes from 3.8.3: Fix assertion failure when verifying a certificate chain with a cycle of cross signatures. CVE-2024-0567 GNUTLS-SA-2024-01-09 Closes: #1061045 Fix more timing side-channel inside RSA-PSK key exchange. CVE-2024-0553 GNUTLS-SA-2024-01-14 Closes: #1061046 Checksums-Sha1: e6cfeb72ef6c6936de9ddc8e2e2779868e65c2e9 872528 gnutls-bin-dbgsym_3.7.1-5+deb11u5_arm64.deb 4f675503bde9516054800bc82dc67261dd2346d1 630896 gnutls-bin_3.7.1-5+deb11u5_arm64.deb d1f50c72cde7591aeb68d067b8b87c1abfcef7a7 11030 gnutls28_3.7.1-5+deb11u5_arm64-buildd.buildinfo 5258f0e37314f7a0d706e7968fdd649055a36806 229624 guile-gnutls-dbgsym_3.7.1-5+deb11u5_arm64.deb d2b333f5ed209dc529faad40e3575058d9bbf4fe 444528 guile-gnutls_3.7.1-5+deb11u5_arm64.deb 283f29cb7fc63e14b101616cad8000e2e3a5f5a7 64560 libgnutls-dane0-dbgsym_3.7.1-5+deb11u5_arm64.deb 4823c4f5751e37c742cb2278cb26128585f5e184 393196 libgnutls-dane0_3.7.1-5+deb11u5_arm64.deb c4d7888a40028e626db515ab3aa4aff9656f7318 65000 libgnutls-openssl27-dbgsym_3.7.1-5+deb11u5_arm64.deb 6526cd4fe6bb8f10e1c3dd7fcd4228be7c022ec0 393256 libgnutls-openssl27_3.7.1-5+deb11u5_arm64.deb b653003f2d431dd1e0ac1aa52be67ecc9451223d 1325524 libgnutls28-dev_3.7.1-5+deb11u5_arm64.deb 40f442ef35fafb0df39d3e5200c46eb44ae383f7 1958828 libgnutls30-dbgsym_3.7.1-5+deb11u5_arm64.deb 70ad15dda5d4b3b005802bb3c4ecc2aaf60f21cf 1262288 libgnutls30_3.7.1-5+deb11u5_arm64.deb d45c743b37c461371961fa475f697f0d51ce236c 50448 libgnutlsxx28-dbgsym_3.7.1-5+deb11u5_arm64.deb d8ad80397fc60c55a0fcd88063a2c568cb97c805 13104 libgnutlsxx28_3.7.1-5+deb11u5_arm64.deb Checksums-Sha256: adc6fe2d6b6685ab0e0401bbe4cdae02d4b3ab12cd79ec08f7e778801756f645 872528 gnutls-bin-dbgsym_3.7.1-5+deb11u5_arm64.deb 5f1b6e4ad9bda0a1567f78e2f777b8f5fc7affbee89040aad1b25e83dec18556 630896 gnutls-bin_3.7.1-5+deb11u5_arm64.deb 3d01545fb21f1b1ca66a48b5d91a7d448c1d9fa19c1da8fc5ce6dc1909ecb0b0 11030 gnutls28_3.7.1-5+deb11u5_arm64-buildd.buildinfo df416d3ffa296da33bfaf1bd7db887df91d0f8352522565e874901c2187bb1ee 229624 guile-gnutls-dbgsym_3.7.1-5+deb11u5_arm64.deb eadab91c52ba426738f2f2fba341e54a7dcbf15897d2dca1b8148096c43b10cd 444528 guile-gnutls_3.7.1-5+deb11u5_arm64.deb 811b07de126eff5b5ddc4511fa7f32d36c6cded081152f5fb591fc49a48bb13c 64560 libgnutls-dane0-dbgsym_3.7.1-5+deb11u5_arm64.deb 5d7ff35f57f16d83cce40fb65249f57cfb6800b24af5cc101635a5a93e757920 393196 libgnutls-dane0_3.7.1-5+deb11u5_arm64.deb 84b53b661729ef314b546977ee941b3248b1c9944892f3658c3c152fa7023235 65000 libgnutls-openssl27-dbgsym_3.7.1-5+deb11u5_arm64.deb 9ee7de46fed520e3ca70475ea5b1465def766e796c70891876ffbd96764885f6 393256 libgnutls-openssl27_3.7.1-5+deb11u5_arm64.deb 2922dd13f0c00d5a519259f3501fccb7bf38a7f42ae2a45f6cc9f41439d1da42 1325524 libgnutls28-dev_3.7.1-5+deb11u5_arm64.deb 6a15651299ea737bba4dde14410a2d4125a4c4ffb543de54bd79104362515b49 1958828 libgnutls30-dbgsym_3.7.1-5+deb11u5_arm64.deb 1f08bdc5db597cf1f5d7f79f66a714b5b1be454e68b4208f04cfb06058610124 1262288 libgnutls30_3.7.1-5+deb11u5_arm64.deb 43377533c9e5d8bd59ffaa1acf6be4575117e5dee21497af9e7f3a83c543e3e0 50448 libgnutlsxx28-dbgsym_3.7.1-5+deb11u5_arm64.deb 3e97e4918f61027bd0192c86efcae2fe9fb5684ef4e184b9fcb0f5105b1a9682 13104 libgnutlsxx28_3.7.1-5+deb11u5_arm64.deb Files: 87b3bd4152c59f6bdf52bcb15e8142a4 872528 debug optional gnutls-bin-dbgsym_3.7.1-5+deb11u5_arm64.deb de7f0f04bf5a209adf587f1176797533 630896 net optional gnutls-bin_3.7.1-5+deb11u5_arm64.deb 7aa1d5dc74fa5ed15f195c75523f5527 11030 libs optional gnutls28_3.7.1-5+deb11u5_arm64-buildd.buildinfo 4bc4c34a6afabc31d8413b2ab51c5827 229624 debug optional guile-gnutls-dbgsym_3.7.1-5+deb11u5_arm64.deb 5bbb8367681c5dea7b3a50a7864794aa 444528 lisp optional guile-gnutls_3.7.1-5+deb11u5_arm64.deb cab2fa0108c0c3ea811d41aad872b316 64560 debug optional libgnutls-dane0-dbgsym_3.7.1-5+deb11u5_arm64.deb 57e4b83d9e26f31d75a185dba3022ef8 393196 libs optional libgnutls-dane0_3.7.1-5+deb11u5_arm64.deb d8d3aa0ad47ff4100d171ebe9d165df0 65000 debug optional libgnutls-openssl27-dbgsym_3.7.1-5+deb11u5_arm64.deb 91ced23bf13b4c91e583ac6fb1d1ce29 393256 libs optional libgnutls-openssl27_3.7.1-5+deb11u5_arm64.deb 75ae083b76f88165f171c00e42f60cfa 1325524 libdevel optional libgnutls28-dev_3.7.1-5+deb11u5_arm64.deb f1e4615be61573aeb9d44adaa4326d86 1958828 debug optional libgnutls30-dbgsym_3.7.1-5+deb11u5_arm64.deb 17192c09de649116f42929ef16609483 1262288 libs optional libgnutls30_3.7.1-5+deb11u5_arm64.deb 1ec161e641084375a1049954743d8ace 50448 debug optional libgnutlsxx28-dbgsym_3.7.1-5+deb11u5_arm64.deb 9ee243a55aa81a764077d2c528e9838d 13104 libs optional libgnutlsxx28_3.7.1-5+deb11u5_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEElif5H+pIB11ZS5Aay8vyjiVDuNYFAmYMcq8ACgkQy8vyjiVD uNaNdg/+PJPciVaxxAVFe6iAPPpdYn1Bwc4DUBfwZtV3U/O3T9wknsEuGB9Dl9Uh mYfae7VrLAocGveHalTjB1ijyKDJOlXvKpCD3ma0fRbNI02NYEjdU9kbZE2KI+vt 5sWFX+3gWWaARb9bYrZKOzXn7GVu/oOE/so1XKvhanoDzf/4xJ0cv9AbMyY52hs5 fI9J4O1W6V9THuUqfdvyOXmfAodgUfzGmoTrzev422aOB/WIqRAZNjJHbX3Z8bqG OUa2R5Jmx97nxoDWkfG2dbBCrnzpkNcr2G0FA1uZ93zY161r64L4CbAYC823cPAl 8Zg0jpeZPNWO1myIak93a/Xj4K5BJds1X6066yV18uYZllKXkbQS51KDPEZXva/u P6pc+XFEoxBNmEcH033c8voHg0B5culBLGi36iM/UevP3ffm3tyOmJ1W8BWA3off 3lIhs9gAtks9oCug9ecW7mEj3IW7R/5AV9Th+NfCt774JiLV9AiQRDijsg7HREkp S+LBoMqYQhkxFP+Qq/vxS6LQEtHoj0gps5asDXop4xZa5Xfwh/fHzMIZ/O8I1+zT palW4HvygnSukZB2PIsl4QvmU6DqXLexDKLou1P0QsBup06DwRnDCJ0xgNJnN+Qx yum/hi4ELlEZRLLWuTydq7gpfixMG6mGEamx0yyivtZeTB3o7uE= =+o/c -----END PGP SIGNATURE-----