-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 16 Jul 2024 10:44:03 +0000 Source: putty Binary: pterm pterm-dbgsym putty putty-dbgsym putty-tools putty-tools-dbgsym Architecture: s390x Version: 0.78-2+deb12u2 Distribution: bookworm Urgency: medium Maintainer: s390x Build Daemon (zandonai) Changed-By: Bastien Roucariès Description: pterm - PuTTY terminal emulator putty - Telnet/SSH client for X putty-tools - command-line tools for SSH, SCP, and SFTP Changes: putty (0.78-2+deb12u2) bookworm; urgency=medium . * Non-maintainer upload. * Cherry-pick from upstream: - Add an extra HMAC constructor function - Fix CVE-2024-31497: biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. In other words, an adversary may already have enough signature information to compromise a victim's private key, even if there is no further use of vulnerable PuTTY versions. * Run test/cryptsuite.py during build. Checksums-Sha1: 2d376ce54f1a15775d25945f6bd7b1569464cec0 687924 pterm-dbgsym_0.78-2+deb12u2_s390x.deb 14a89ba0574b9fdfb53270605130b50d106fb753 213128 pterm_0.78-2+deb12u2_s390x.deb ab0894ae69b9ec525193224aa5a28bfdc71d71ad 2299492 putty-dbgsym_0.78-2+deb12u2_s390x.deb 33369b4cafdf8d1d2a7e4f6dbad17a5001361db6 4723164 putty-tools-dbgsym_0.78-2+deb12u2_s390x.deb 2194547a05966e226267c59711f9012ca43b070d 568192 putty-tools_0.78-2+deb12u2_s390x.deb ed2841766e8692f610496ee5f1cc3dbf4419465e 16248 putty_0.78-2+deb12u2_s390x-buildd.buildinfo e8248966c372e2582d8a9130ef008b12f7197623 496236 putty_0.78-2+deb12u2_s390x.deb Checksums-Sha256: 45800c1fbf33b12b2a4038b7dd7f8724bf0bf24f9b7aa64f59d3410319dd7fed 687924 pterm-dbgsym_0.78-2+deb12u2_s390x.deb b2ef2d51e412f0c1d78616e4b69c9333f5fa132a5cbb82c0bf99943cc638e5df 213128 pterm_0.78-2+deb12u2_s390x.deb 69f86debb999ea5b149a79bddd36166ccd656d9b7b5f28e292f32b4d3c8f286b 2299492 putty-dbgsym_0.78-2+deb12u2_s390x.deb 6728ec77dca019b26939f482dc079ebe335263e2fffff9a36b5523f410ed333c 4723164 putty-tools-dbgsym_0.78-2+deb12u2_s390x.deb 669250e2a442f7f45789759e9dd5770700cc711efb736765f39208074c65a75d 568192 putty-tools_0.78-2+deb12u2_s390x.deb c04311eef2303ebb9a2abd7169e5412ffe63b398a39f4cb74690d8256b342377 16248 putty_0.78-2+deb12u2_s390x-buildd.buildinfo 439d65cffd1abb9e6ed57c55ea2e77dadf0f76a1a8069b5a1c2198c5bd7a8639 496236 putty_0.78-2+deb12u2_s390x.deb Files: 07063a8e17f6716bd122a221aa16fca5 687924 debug optional pterm-dbgsym_0.78-2+deb12u2_s390x.deb 55c28c047932fab8847580f794913c94 213128 x11 optional pterm_0.78-2+deb12u2_s390x.deb c51c72fc526c93434c2d609e7c9b82cd 2299492 debug optional putty-dbgsym_0.78-2+deb12u2_s390x.deb 4bb510067771f7c31b477b5cddd7a45e 4723164 debug optional putty-tools-dbgsym_0.78-2+deb12u2_s390x.deb 41f270ab417add0402453877909e52c3 568192 net optional putty-tools_0.78-2+deb12u2_s390x.deb 27eb83c96f356d937f05f83f852cf556 16248 net optional putty_0.78-2+deb12u2_s390x-buildd.buildinfo ff8ee09c5dc367037797dea641bef6ec 496236 net optional putty_0.78-2+deb12u2_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEctqRAwcjFMIrbct74euoNlQ3ywQFAmbGayQACgkQ4euoNlQ3 ywTWEQ/8C27G6lXU2dvT73v/tWjk9IxmDXx6ga9+MkPf/oYNfB+S0ZDrIpgPbvBz qEvYw4TjvX5YPFbVqwai/hxafSjxYpLnBKzUKolVS2d7YyFOfNguwzsx7IeU+KYB w95CQHknI16GjXWVXBkjFo+0jrNXIIP7yin9aYGNBBfhvKkyj1HcvoF2DeHFltVA lb+SriBkngdOUcVDMLiezGs/06FDMJ2Ebd6cenCpiNaC65ZBlSkqle1qpyujcG6m W68KSR8zhTgFCn0R2afB5uYHzyipAon2kLPK3sKwYvP3dXNUVu5ffvgr2FJj3mgn hf4a9Z0craQShn2FmDe6r6i3VQf4DI8gqORTieGaqfD2658/wWMJI5+JYG1Rkdga if0CNxhHUgdiPESEz5tlv/swIyvev/mQgEnSxgwD/FN9tI7umR/X0LLtV6vNigyi D+YU+NhL+A5ZvHVA9OPlELx8hIuaVQPEt5Pj3aEVY720Kowv+7lylZiZqdE579nq sWqVHJiPN3gSiPG18+wGDORakHKMmy21GzaHOF9MKgyrTJQ7oWAvczh3QkA+KSEu rstoLT5difqg+60SRN6WoweZhz4Tf2po/wfclPtl3zV4gEKSOY+DG1CXLHEVLrKe bxS7JRZ6AxKb+Gezlmch2L51Qx+jH896GVf0sguks2ivpttp+kk= =t487 -----END PGP SIGNATURE-----