-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 20 Jan 2024 07:56:15 +0100 Source: gnutls28 Binary: gnutls-bin gnutls-bin-dbgsym guile-gnutls guile-gnutls-dbgsym libgnutls-dane0 libgnutls-dane0-dbgsym libgnutls-openssl27 libgnutls-openssl27-dbgsym libgnutls28-dev libgnutls30 libgnutls30-dbgsym libgnutlsxx28 libgnutlsxx28-dbgsym Architecture: ppc64el Version: 3.7.1-5+deb11u5 Distribution: bullseye Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-conova-01) Changed-By: Andreas Metzler Description: gnutls-bin - GNU TLS library - commandline utilities guile-gnutls - GNU TLS library - GNU Guile bindings libgnutls-dane0 - GNU TLS library - DANE security support libgnutls-openssl27 - GNU TLS library - OpenSSL wrapper libgnutls28-dev - GNU TLS library - development files libgnutls30 - GNU TLS library - main runtime library libgnutlsxx28 - GNU TLS library - C++ runtime library Closes: 1061045 1061046 Changes: gnutls28 (3.7.1-5+deb11u5) bullseye; urgency=medium . * Cherrypick two CVE fixes from 3.8.3: Fix assertion failure when verifying a certificate chain with a cycle of cross signatures. CVE-2024-0567 GNUTLS-SA-2024-01-09 Closes: #1061045 Fix more timing side-channel inside RSA-PSK key exchange. CVE-2024-0553 GNUTLS-SA-2024-01-14 Closes: #1061046 Checksums-Sha1: dee711dce64b1c4528ed61d47b42579e5babc905 905228 gnutls-bin-dbgsym_3.7.1-5+deb11u5_ppc64el.deb c3f7301ca49c8348deb2cdc4e225967559149dd5 646772 gnutls-bin_3.7.1-5+deb11u5_ppc64el.deb f013405930aa80acc7aed3d570d921cc1850fe40 11144 gnutls28_3.7.1-5+deb11u5_ppc64el-buildd.buildinfo aff755a6fdc04b60286308da10019520ce3966b7 236680 guile-gnutls-dbgsym_3.7.1-5+deb11u5_ppc64el.deb 4a0d2aefd364bb3c80a71a6fe226b236b36f70c4 448312 guile-gnutls_3.7.1-5+deb11u5_ppc64el.deb 5992c3124bc41ba796d37f0067f484209f55a751 67276 libgnutls-dane0-dbgsym_3.7.1-5+deb11u5_ppc64el.deb 98bd1cdfeae2e91c537037d7113ea00fca8b1e13 396076 libgnutls-dane0_3.7.1-5+deb11u5_ppc64el.deb 50b84d3c0c0e007cf6ef9ae157e09e497f7bfb6c 67944 libgnutls-openssl27-dbgsym_3.7.1-5+deb11u5_ppc64el.deb 034acf645c98882e437664c29ba734b67ca75647 395736 libgnutls-openssl27_3.7.1-5+deb11u5_ppc64el.deb 3f5387a0a870c932a2582b618c004d22d01b463b 1365104 libgnutls28-dev_3.7.1-5+deb11u5_ppc64el.deb 2fa9566f98925a39e990c98301a64d979274b540 1909152 libgnutls30-dbgsym_3.7.1-5+deb11u5_ppc64el.deb 99cee80fcff453598c7987bc90774167a4d0e5a2 1315008 libgnutls30_3.7.1-5+deb11u5_ppc64el.deb 54a55b19c3f9da3c4b0a845b76504d3e213f6f97 51564 libgnutlsxx28-dbgsym_3.7.1-5+deb11u5_ppc64el.deb e95f3d52e0b02f08e90a596d1922d123264df651 14644 libgnutlsxx28_3.7.1-5+deb11u5_ppc64el.deb Checksums-Sha256: c85feb55a8d85f5cb3e9a81860bc3d9098412a147e6cbfb2af285ed19a26eedd 905228 gnutls-bin-dbgsym_3.7.1-5+deb11u5_ppc64el.deb 7c9a5ebf97da34bcc36602bde407c4b9eb7565310f62cb43d65fab51c34bc738 646772 gnutls-bin_3.7.1-5+deb11u5_ppc64el.deb 0d91b24197871163ca9852339ecd52ae250b6550ef2bd4f8a04cbc492a22d239 11144 gnutls28_3.7.1-5+deb11u5_ppc64el-buildd.buildinfo 00c97dad34e4ff09521418cb8f274d8e0635f580ad2783818d257c3e2e51b5d9 236680 guile-gnutls-dbgsym_3.7.1-5+deb11u5_ppc64el.deb c9291bf6a46e475e5e089473290e2de40d1192fc1d759a0401ae899f9395b8ef 448312 guile-gnutls_3.7.1-5+deb11u5_ppc64el.deb f4abaf64fd18cffb578ced6dbd80a0024bb08ee9d87cced6e4158936f7b41d4a 67276 libgnutls-dane0-dbgsym_3.7.1-5+deb11u5_ppc64el.deb 5e0d2cde7d79d14b2d12406685b384b053338960e58de969c1bbef95513639f0 396076 libgnutls-dane0_3.7.1-5+deb11u5_ppc64el.deb 0e4d0a0d3f3560e077d0672a1d44d05d7c4a4594a13fe7fe5d73424e97fce8dd 67944 libgnutls-openssl27-dbgsym_3.7.1-5+deb11u5_ppc64el.deb d7780da32c98939f53c062b96ac5d9975a21b4064800bb811fe879492eebc889 395736 libgnutls-openssl27_3.7.1-5+deb11u5_ppc64el.deb 429f44af4291dd01d95d03d8dd5f94a9801b829c757d42c8612272d44ca46fa1 1365104 libgnutls28-dev_3.7.1-5+deb11u5_ppc64el.deb c349df6a6af1133031f41fb7f6d5d4633133834685eceb530e3bf7dd7742342b 1909152 libgnutls30-dbgsym_3.7.1-5+deb11u5_ppc64el.deb 63e8de4ee9d34eca04ef551712fe2bad89b6e55cf06b377a4879633aa12fbf71 1315008 libgnutls30_3.7.1-5+deb11u5_ppc64el.deb 970624a8dc52d91e1a40daead13f6b6f301e1ea9f72ed6ff751f308de2dad51a 51564 libgnutlsxx28-dbgsym_3.7.1-5+deb11u5_ppc64el.deb d324ca88a092e36b63b659b7b4d4c32c12ece510060123e6bc205a694ff432f2 14644 libgnutlsxx28_3.7.1-5+deb11u5_ppc64el.deb Files: 7616fdd7bf2a85b9351f95dd08d0ddc9 905228 debug optional gnutls-bin-dbgsym_3.7.1-5+deb11u5_ppc64el.deb 4044ba181482c1d29b21383b5849c84b 646772 net optional gnutls-bin_3.7.1-5+deb11u5_ppc64el.deb f32d2e164d69616a30880686f86ffca4 11144 libs optional gnutls28_3.7.1-5+deb11u5_ppc64el-buildd.buildinfo 39cee2c86590216e89128900a63c4569 236680 debug optional guile-gnutls-dbgsym_3.7.1-5+deb11u5_ppc64el.deb bff2d2e59fac21f3a9d0f4f4f00ecb8b 448312 lisp optional guile-gnutls_3.7.1-5+deb11u5_ppc64el.deb 8fd30b9f6183f9788b5b128c4a78c592 67276 debug optional libgnutls-dane0-dbgsym_3.7.1-5+deb11u5_ppc64el.deb 78b2b5a74a815ee47c2c7e1ad4efdd07 396076 libs optional libgnutls-dane0_3.7.1-5+deb11u5_ppc64el.deb 4bd3e1b47061c95fe5288585e3807015 67944 debug optional libgnutls-openssl27-dbgsym_3.7.1-5+deb11u5_ppc64el.deb d061fff0a04384983ceb5499aab7c91d 395736 libs optional libgnutls-openssl27_3.7.1-5+deb11u5_ppc64el.deb e5c17bb8176a083d12a7534ab3fa679d 1365104 libdevel optional libgnutls28-dev_3.7.1-5+deb11u5_ppc64el.deb 93361000ad48bbf75ca72e5c3d4c1790 1909152 debug optional libgnutls30-dbgsym_3.7.1-5+deb11u5_ppc64el.deb d316205049e9e7bb7228a41434a40062 1315008 libs optional libgnutls30_3.7.1-5+deb11u5_ppc64el.deb 598824b7ea2884262ba09bbf2dff4618 51564 debug optional libgnutlsxx28-dbgsym_3.7.1-5+deb11u5_ppc64el.deb 9b5a95625715f494f2044976e1841e3a 14644 libs optional libgnutlsxx28_3.7.1-5+deb11u5_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE8YyVP0bbbFwKPsGN0jKBgzfto4IFAmYMcq4ACgkQ0jKBgzft o4J6lg/+JjuybRsRrXYuHwVe0aILDcmcAxvpUUuh8DIT4CPbG6horVmqeLyL0VoZ UDv6oJ3ug28uU4n69rPn7C3KroQ1KBx9tc7su6bOd50w76EizXE1vzZEasUewMJY 6xkfqUtE7yJ0XLv9dy2x/kn03iUfllWJup4SQUN31vM1WkfqWCbkTdW50iWMph6q 8y33b4NurOKMooni8kN2WsWKbkOsUJixWt2vsmgKdrXwyB+CdM7pQ4+AE2Z76ozh ubQgSV47nbGKaJmZavg/Wuto+NW8sEj6WU8TKPIUoPriO7rgPPjDKh2+WpxSX3VX q79VAvN2+GVY3ay80fANvQEJ1Q37vhWHferJDqq85D1tm9PwPM3pPeQIk4t2MCbO HNXB0eW/GldGHocQDI5WjbQkOOSJMaQJDAgykHtr0s8XqJr7i7SHs/KmrJbbBVu+ 7RWaBJc43I5QVtxUmVv5344Q7vYOQaSDLIhQioTNVstCOqoPtqRXA8+AkoobIiN9 ZhaD3BYavFKkny7CWozUlbcixLRmt+2rFXGNdiuxWJPXV7be4zCx9AIR+ogOLpY/ 85O9jtRBFFhimMj8/ZkWaMm3PVFEBo3FldAqH2u9/Urgy9wThaIHfoEjeKC5quEf 8s5AVQ3PVogYryEzKItrCl1c8yYI5cmi2rMxw0oNPRxU2kMmodA= =5j5J -----END PGP SIGNATURE-----