-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 16 Jul 2024 10:44:03 +0000 Source: putty Binary: pterm pterm-dbgsym putty putty-dbgsym putty-tools putty-tools-dbgsym Architecture: armel Version: 0.78-2+deb12u2 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-conova-02) Changed-By: Bastien Roucariès Description: pterm - PuTTY terminal emulator putty - Telnet/SSH client for X putty-tools - command-line tools for SSH, SCP, and SFTP Changes: putty (0.78-2+deb12u2) bookworm; urgency=medium . * Non-maintainer upload. * Cherry-pick from upstream: - Add an extra HMAC constructor function - Fix CVE-2024-31497: biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. In other words, an adversary may already have enough signature information to compromise a victim's private key, even if there is no further use of vulnerable PuTTY versions. * Run test/cryptsuite.py during build. Checksums-Sha1: 8573ddde7d06bb8eedff1a9b0269dcb5eea2df87 687600 pterm-dbgsym_0.78-2+deb12u2_armel.deb 70a934e4d97955dd498a1562da07ac5d91f0e63f 193564 pterm_0.78-2+deb12u2_armel.deb 669bbd7cd0617ccf35352e21105f651f302236d6 2263116 putty-dbgsym_0.78-2+deb12u2_armel.deb 594944764ed2285f22be493bf707236377bee6b1 4634192 putty-tools-dbgsym_0.78-2+deb12u2_armel.deb 38dce26b4d601487405497087e67e5af813083c1 474492 putty-tools_0.78-2+deb12u2_armel.deb 10fee3e4908e759974df207ba9c310397aad6f8a 16281 putty_0.78-2+deb12u2_armel-buildd.buildinfo 0decc98d1eda757bf4bc17f8c3dd25c5c70bd789 442180 putty_0.78-2+deb12u2_armel.deb Checksums-Sha256: 10d11ad647fc8c430b81f986eb583e1046270f2546f5837d19a9f578d017ee13 687600 pterm-dbgsym_0.78-2+deb12u2_armel.deb 1eff57a7de1a0849978fc9d32cdc4818551fddc52bdfee8a9ce847421edc6c3e 193564 pterm_0.78-2+deb12u2_armel.deb 7bacbbfa918aa06fb08ce44992f167924053aef7d0560049231ce59fc14b25c8 2263116 putty-dbgsym_0.78-2+deb12u2_armel.deb 77ee35053c34b1b4bdd5787c8b193575ed8be43c3189c3d1dc5faa576125bdfe 4634192 putty-tools-dbgsym_0.78-2+deb12u2_armel.deb 522e40ab40c3b91edcb9cbffbaa227d4b4dd5899ac654027dd7087851e206de6 474492 putty-tools_0.78-2+deb12u2_armel.deb 03953908cf1211eb46315cd7405e016d217e0f9e44dc7f40b28c7f7f46b45d4e 16281 putty_0.78-2+deb12u2_armel-buildd.buildinfo 820d0377e0cfe8ed97613413973dd32b601756e7d759f2279669ec80238528d1 442180 putty_0.78-2+deb12u2_armel.deb Files: 14d78f49cbe80389b221d256e98800f5 687600 debug optional pterm-dbgsym_0.78-2+deb12u2_armel.deb 3afede09cd6f302d645a1df6a50589c4 193564 x11 optional pterm_0.78-2+deb12u2_armel.deb 45910fe37ae383e49af527ed1b5d4732 2263116 debug optional putty-dbgsym_0.78-2+deb12u2_armel.deb a4140295e7117a34b7dc5e2952d60798 4634192 debug optional putty-tools-dbgsym_0.78-2+deb12u2_armel.deb 3352c5d933dbe843ae3ae67e1730f5ed 474492 net optional putty-tools_0.78-2+deb12u2_armel.deb e5792be3d091f4a5accbe153a3e3aa79 16281 net optional putty_0.78-2+deb12u2_armel-buildd.buildinfo d6fbf6f94addfdf07d969a3df88582a5 442180 net optional putty_0.78-2+deb12u2_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKAzExpjGvTI78ZO8LARVyvnD3xkFAmbGZb0ACgkQLARVyvnD 3xnYUBAAg0t5AhW3jIBa8PuhevXLu8LZjzCFrHSiZL9jNvaoVG1+5g16V0u1J9P9 85T77Kn7M/3dY3rt0YfPJio7au98SNdLcm2mtC8+1FCTvArpDl6jEAhu0NrpA7/a La+ghYTyJ8Q32o50hyO44oGgtY7ckvBPg4nd85LwTVvCldv1LkcUSV9HjpPFEhRr Y9ZIVsuFu4Pdz0NuPxbmmZXnJ+li8DBDuKpavo88bA25GGxEaNMthc1JpvnL9LZd uPr+w11y/mIe78sM1EeqorVC8mLLYpFWog2CHe775qK/8K5CL/Ks001THcIajfIY XjhhQV76e26PJhjbQh8dubjWF/H/hWlXGuDL9n2zRGkPXr4z9gfGjomAt5wOFRRt KV+2Uw+G+17UqfBpLaBBDO/bJnKX+8emfRFtqIzTRp3bK8wn7uzdcMo2l6fgXgMn YgD8YxuY5WBmKo5xvZrg5hcSqg7SY2GM9OWlQJjkY7Eg3mdDE7D16B3KOlgFzItF 2A63lrEtVAlHFx4btVLkLUJQlWSPbQbrA8zsQObfhaqwxjFxWvEaro4W7ZBpgpv6 6PVQn6W9/mGAjvslMx1tTkXzdMzQU6la0sXkRxZvI4DM7tlhrST92oQb8GgLvYeP wm1DknOM8/d1eSEOuaU/lJsrPevONY9ijjMkVfzo7KC7ukv3XIE= =DlxO -----END PGP SIGNATURE-----