-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 12 Jun 2019 19:21:23 +0200 Source: gnutls28 Architecture: source Version: 3.6.7-4 Distribution: unstable Urgency: medium Maintainer: Debian GnuTLS Maintainers <pkg-gnutls-maint@lists.alioth.debian.org> Changed-By: Andreas Metzler <ametzler@debian.org> Closes: 929907 Changes: gnutls28 (3.6.7-4) unstable; urgency=medium . * Cherry-pick important bug-fixes from 3.6.8: + 40_rel3.6.8_01-gnutls_srp_entry_free-follow-consistent-behavior-in.patch The gnutls_srp_set_server_credentials_function can be used with the 8192 parameters as well. https://gitlab.com/gnutls/gnutls/issues/761 + 40_rel3.6.8_05-lib-nettle-fix-carry-flag-in-Streebog-code.patch Fix calculation of Streebog digests (incorrect carry operation in 512 bit addition). + 40_rel3.6.8_10-ext-record_size_limit-distinguish-sending-and-receiv.patch Fix compatibility of GnuTLS 3.6.[456] server with GnuTLS 3.6.7 client. Closes: #929907 + 40_rel3.6.8_15-Apply-STD3-ASCII-rules-in-gnutls_idna_map.patch Apply STD3 ASCII rules in gnutls_idna_map() to prevent hostname/domain crafting via IDNA conversion. https://gitlab.com/gnutls/gnutls/issues/720 + 40_rel3.6.8_20-pubkey-remove-deprecated-TLS1_RSA-flag-check.patch Fixed bug preventing the use of gnutls_pubkey_verify_data2() and gnutls_pubkey_verify_hash2() with the GNUTLS_VERIFY_DISABLE_CA_SIGN flag. https://gitlab.com/gnutls/gnutls/issues/754 Checksums-Sha1: 405d4ec39e90160436e9f6dce356d8b28fbba1bf 3322 gnutls28_3.6.7-4.dsc f4c7014c5653ea59b5778e6a0770087e1aa21efb 72820 gnutls28_3.6.7-4.debian.tar.xz Checksums-Sha256: ff2e35284ef8002260f628ef2aef82f8f9859ff9ed125e087a97b5490e5ee338 3322 gnutls28_3.6.7-4.dsc fac0e4910dff5eddc6e25709438f3b3c70239b202f079c4466e81a6fd4cb8a82 72820 gnutls28_3.6.7-4.debian.tar.xz Files: 0050731f170e0d4251afd1d58bf2d69b 3322 libs optional gnutls28_3.6.7-4.dsc 61b86dfcb696d1cf003b9e0a193bd834 72820 libs optional gnutls28_3.6.7-4.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0uCSA5741Jbt9PpepU8BhUOCFIQFAl0BOOsACgkQpU8BhUOC FITyOA//Qk3aL25v/IDxmexqtCVp8PGyCK27YhfvJQkCvCh+L0teVIhFKrmWpIvs JtoGraBVYi6NR7+Ua//Z8Pha72CxcpV64+kdgj08qDmA1UE6kCWdupv7kgZT9j9s FN+v4IWHY9MIYadOd8U3XLtfJjjHv7BA01orpzvXCwTc+B86MYEdJFndsDoMljOD +elBRWTOAwI0hZRJyyVYmsugb4QOMf3/dfZUvJ12KTr5uhp0G2uAjfDntmDwxVQE 5mkgJ9S7ZhXaP6ml/dLTJzdPWqNKFxK0AnxN2FNtYxY5NyonbjgF8DrWCACEK9dU Q7FHa7x+pEaR4xXFSYlgrMmn2Q9ThJpCgo1Ju5dNfJm+NdIsmaMtn54sc6gMtdPz nynafzofpcrnlOC9k0u5MQvZ8eEsIjXfnfuDBvWnO/wQuXtvkHxH6VIo+3Xlh9Za CrJ5igON1E42y54SdTGZy3ajXLmiJT5FFdPXNd3VCK4XaLXzOuaeMCBJ3G5AFndc oIgGF9+QOKiYNrDIgp4zq/7eNy+V7NB5mcpNByUz0sO7WTRPZdk+5HqjEWV4logu Zov4akNAZFhqybggFwlv/TQsletvz0jHMDbILUA1G0fhIIxIqjKL6+0QZ5JUTzz+ F72g/IjPSfMfK418l8AheNOSMtdpdtjtfZGFZ2uA0LnAcDVHe6Y= =rGW2 -----END PGP SIGNATURE-----