-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 15 Jun 2024 13:22:35 +0200 Source: gnutls28 Binary: gnutls-bin gnutls-bin-dbgsym guile-gnutls guile-gnutls-dbgsym libgnutls-dane0 libgnutls-dane0-dbgsym libgnutls-openssl27 libgnutls-openssl27-dbgsym libgnutls28-dev libgnutls30 libgnutls30-dbgsym libgnutlsxx30 libgnutlsxx30-dbgsym Architecture: s390x Version: 3.7.9-2+deb12u3 Distribution: bookworm Urgency: medium Maintainer: s390x Build Daemon (zani) Changed-By: Andreas Metzler Description: gnutls-bin - GNU TLS library - commandline utilities guile-gnutls - GNU TLS library - GNU Guile bindings libgnutls-dane0 - GNU TLS library - DANE security support libgnutls-openssl27 - GNU TLS library - OpenSSL wrapper libgnutls28-dev - GNU TLS library - development files libgnutls30 - GNU TLS library - main runtime library libgnutlsxx30 - GNU TLS library - C++ runtime library Closes: 1067463 1067464 Changes: gnutls28 (3.7.9-2+deb12u3) bookworm; urgency=medium . * Update to 3.7.11: + Replace 60-auth-rsa_psk-side-step-potential-side-channel.patch 61-x509-detect-loop-in-certificate-chain.patch 62-rsa-psk-minimize-branching-after-decryption.patch with versions from gnutls_3_7_x branch instead of manual backports from 3.8.x. + Add 53-fips-fix-checking-on-hash-algorithm-used-in-ECDSA.patch (Fix checking on hash algorithm used in ECDSA in FIPS mode) and 54-fips-mark-composite-signature-API-not-approved.patch (Mark composite signature API non-approved in FIPS mode.) to allow straight cherry-picking of later patches. + 63_01-gnutls_x509_trust_list_verify_crt2-remove-length-lim.patch libgnutls: Fixed a bug where certtool crashed when verifying a certificate chain with more than 16 certificates. Reported by William Woodruff (#1525) and yixiangzhike (#1527). [GNUTLS-SA-2024-01-23, CVSS: medium] [CVE-2024-28835] Closes: #1067463 + 63_02-nettle-avoid-normalization-of-mpz_t-in-deterministic.patch libgnutls: Fix side-channel in the deterministic ECDSA. Reported by George Pantelakis (#1516). [GNUTLS-SA-2023-12-04, CVSS: medium] [CVE-2024-28834] Closes: #1067464 + 63_03-serv-fix-memleak-when-a-connected-client-disappears.patch Fix a memleak in gnutls-serv when a connected client disappears. + 63_04-lib-fix-a-segfault-in-_gnutls13_recv_end_of_early_da.patch Fix a segfault in _gnutls13_recv_end_of_early_data(). + 63_05-lib-fix-a-potential-segfault-in-_gnutls13_recv_finis.patch Fix a potential segfault in _gnutls13_recv_finished(). Checksums-Sha1: 4c6c6ad3730eb143562653782fcd6da5e4d19cb3 822960 gnutls-bin-dbgsym_3.7.9-2+deb12u3_s390x.deb b4d750d7dc059098bccf1e75dc6ec5b28bd40435 620992 gnutls-bin_3.7.9-2+deb12u3_s390x.deb ffae56cd496a7bf00ac34f0266b0eb701a7b3b17 11132 gnutls28_3.7.9-2+deb12u3_s390x-buildd.buildinfo 26f89f40cf84df0aa2dbc01850519ca333ff635d 255312 guile-gnutls-dbgsym_3.7.9-2+deb12u3_s390x.deb 721a8f8ce366f771465c4f87a2641286774986ef 457528 guile-gnutls_3.7.9-2+deb12u3_s390x.deb 5d7df0ab46050947bf93a372a5ff75743f423070 89980 libgnutls-dane0-dbgsym_3.7.9-2+deb12u3_s390x.deb 9c38b38f96b096f455ac8de741321f0f6f6537d7 404492 libgnutls-dane0_3.7.9-2+deb12u3_s390x.deb 1b4e2d1be8e73c19b56581cc843185014194f385 91068 libgnutls-openssl27-dbgsym_3.7.9-2+deb12u3_s390x.deb 83a7878cf41b9cffaf1be18b9c1f1303c4771989 404624 libgnutls-openssl27_3.7.9-2+deb12u3_s390x.deb 1dbdd9937c30356ee666cca414d83e1c62ddf2aa 1225736 libgnutls28-dev_3.7.9-2+deb12u3_s390x.deb 5f8a3b76ffc52e18542a68467515bcffd69fea75 1949756 libgnutls30-dbgsym_3.7.9-2+deb12u3_s390x.deb abed76c1aa1a3f8a4a0130c10b1b3f4b38bc227f 1283616 libgnutls30_3.7.9-2+deb12u3_s390x.deb e1b95818c58a607dfe1d33e10adcd02750f1b0d3 48304 libgnutlsxx30-dbgsym_3.7.9-2+deb12u3_s390x.deb 140ec49e54693459157cfda04491cf1a8556ee31 13700 libgnutlsxx30_3.7.9-2+deb12u3_s390x.deb Checksums-Sha256: 24f7da65cdd10a959e6e30a81b65d789776eaf5176744a4dded38766a680c15a 822960 gnutls-bin-dbgsym_3.7.9-2+deb12u3_s390x.deb d1a9a89f3f3e74776c8f56c672fdedf83ccb84ce6f89fa4d41b6a7267b798f38 620992 gnutls-bin_3.7.9-2+deb12u3_s390x.deb 4b40ad1ef67d16d47775c061ac116f7ccc7ef1f9a00cfac50f9d656af4ac2c43 11132 gnutls28_3.7.9-2+deb12u3_s390x-buildd.buildinfo e4b82047888885a1147294b528342845db104ed689f0dc47a19d0446bede5c10 255312 guile-gnutls-dbgsym_3.7.9-2+deb12u3_s390x.deb 8efa93be8fb22c601c6c4fd009febc6bd56c1404cfd847014700aa71cd2f01f2 457528 guile-gnutls_3.7.9-2+deb12u3_s390x.deb f80f2faef0a159076fb951d8ca9c182915870ed23c24c98f57987566b5c5087d 89980 libgnutls-dane0-dbgsym_3.7.9-2+deb12u3_s390x.deb 779eaab33686505fe5624093097aea567c6ddf68a085e8c0b754c5b2fa808c61 404492 libgnutls-dane0_3.7.9-2+deb12u3_s390x.deb addb1c1be9987330b2d8f00f1ef0ecfda405b2f67a22e385d43fb8fa516d9e45 91068 libgnutls-openssl27-dbgsym_3.7.9-2+deb12u3_s390x.deb f42a8a5910dfaa23d24f5f6c982e0f26d3a02099ce43ebbcf6c36f808d461c15 404624 libgnutls-openssl27_3.7.9-2+deb12u3_s390x.deb c4294b7fb1406ac30c10a824865383e498b937bf0a6e047f17f9ec38d69d1699 1225736 libgnutls28-dev_3.7.9-2+deb12u3_s390x.deb 324080d5670a06894904621720f7eb697f8123557897ecd821a6fdd000d73ecc 1949756 libgnutls30-dbgsym_3.7.9-2+deb12u3_s390x.deb 857486143e06968bd1aad7ed926161e1d43ffde1d703ef2c7ff5e9949d988e97 1283616 libgnutls30_3.7.9-2+deb12u3_s390x.deb d1a1be7a8e5fed7c7b64fc3f8e0a0456e3aba229a1fd5e74e7bb596cc7d50a19 48304 libgnutlsxx30-dbgsym_3.7.9-2+deb12u3_s390x.deb 3c612819f5be9ca3d5b5e6b1b1336b930daa13c6116dfdd1ae2958b4ff40b05e 13700 libgnutlsxx30_3.7.9-2+deb12u3_s390x.deb Files: 982d9add3ef56b18848f1d7449a63ab2 822960 debug optional gnutls-bin-dbgsym_3.7.9-2+deb12u3_s390x.deb 6a41b53248a62c470af331d298c23af2 620992 net optional gnutls-bin_3.7.9-2+deb12u3_s390x.deb d22bf944c2fb4d0efcd37d1954a0a091 11132 libs optional gnutls28_3.7.9-2+deb12u3_s390x-buildd.buildinfo 259c626c49cbff2e0764a567ce90cb32 255312 debug optional guile-gnutls-dbgsym_3.7.9-2+deb12u3_s390x.deb 3acde5101facf545bcee222d0414e959 457528 lisp optional guile-gnutls_3.7.9-2+deb12u3_s390x.deb a33ad445ed55f93eabbf1396eb35e822 89980 debug optional libgnutls-dane0-dbgsym_3.7.9-2+deb12u3_s390x.deb 69673d15a8ab70f9ac3b617dd1977d29 404492 libs optional libgnutls-dane0_3.7.9-2+deb12u3_s390x.deb 835e72c929e47098201191fcca763e13 91068 debug optional libgnutls-openssl27-dbgsym_3.7.9-2+deb12u3_s390x.deb d6be1b28a1f657368073be557d268342 404624 libs optional libgnutls-openssl27_3.7.9-2+deb12u3_s390x.deb f7d5df9bfbff66989d8a1a870ce42732 1225736 libdevel optional libgnutls28-dev_3.7.9-2+deb12u3_s390x.deb 523baa2601d2289e0125841e1726a0d2 1949756 debug optional libgnutls30-dbgsym_3.7.9-2+deb12u3_s390x.deb eb78df9866a689ed3ec8e1de7fdb9149 1283616 libs optional libgnutls30_3.7.9-2+deb12u3_s390x.deb b53e13d63904c21c64fb62681ee458f6 48304 debug optional libgnutlsxx30-dbgsym_3.7.9-2+deb12u3_s390x.deb 90826744c0a89fc9041a77fb106f9d1a 13700 libs optional libgnutlsxx30_3.7.9-2+deb12u3_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEETdQgQHyJW2hcXsTC6b+AMjGgQHgFAmZvWOsACgkQ6b+AMjGg QHiSyg//Z68yU2tk57cPHZhfdhR9T80aloWABnrqAaUyxldf6blhL0J9CmDk/Z+H S1sodNUcNT5YUKXUoeLtuHgwxuPKyk7K+hzRxOHxt8PxlQHdHsoH8i9t58BDjjC/ v+t96fxhDVoBzYTtngAcEFmMzoIkWBl8uL2RxOkfbDcO0P/kfzzAolZN1HAkJz1R ZGFlAqRHexdzcq+8P/rbDgVjjxpaVgubht01viwsUlYnHLjHd/3kM3eF8ZKT1i3E ZBbX2AzY7LO+WEourlhDO0sXf0FN8AarAxp+rgAqReYB6YPsKA+4xfuy3ffWJ9lz D0uY1hK6hW7cD01Ofi128JpPTlh9I00XF/dEXRPJ9DWUR2rYJgDTlub5Gz18BdVG 5vrryqy6SBJDWev7GgCpTZox0AGDqwmfuorJ08V0F36O2yXjO0lTLNwhszt9Vi9g 9jQ7gvbgqe+xiTJtPrLBhT4pymQhItES/rCtquKPCdGoJYFGMhALY3QLO1A5qFYY QyEnNA+SOt7d68AwmX7YPxhraEd4D2JhcOdgjT1uFZlJMw2BPq8bBcwaYAHeCmdb a0Pu55nDBGkB3rMnnvsx7SEk7uUEAAqpiWinO71n56w+Pe67ohBsaGSz0hM41bx/ 1u1qXwbSDW3Pe7mOn7AM8cYh9NvctxTSwaR0t1gehQMVNpdLRDw= =Wzn2 -----END PGP SIGNATURE-----