-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 27 Sep 2019 21:29:13 +0200 Source: openssl Architecture: source Version: 1.1.1d-0+deb10u1 Distribution: buster-security Urgency: medium Maintainer: Debian OpenSSL Team <pkg-openssl-devel@lists.alioth.debian.org> Changed-By: Sebastian Andrzej Siewior <sebastian@breakpoint.cc> Changes: openssl (1.1.1d-0+deb10u1) buster-security; urgency=medium . * New upstream version - CVE-2019-1549 (Fixed a fork protection issue). - CVE-2019-1547 (Compute ECC cofactors if not provided during EC_GROUP construction). - CVE-2019-1563 (Fixed a padding oracle in PKCS7_dataDecode and CMS_decrypt_set1_pkey). * Update symbol list Checksums-Sha1: 59bf443f6bd450bcae1513a763429ef211f51568 2472 openssl_1.1.1d-0+deb10u1.dsc 056057782325134b76d1931c48f2c7e6595d7ef4 8845861 openssl_1.1.1d.orig.tar.gz d3bbfe1db19cc36bb17f2b6dc39fa8ade6a8cdd3 488 openssl_1.1.1d.orig.tar.gz.asc 9c06ffb23fb09146b8103bf77bac91b897d4a056 84040 openssl_1.1.1d-0+deb10u1.debian.tar.xz Checksums-Sha256: 7329a436fffa21d398f10ef9108be3cf75495bbb83e38387d7679d12b4eda05e 2472 openssl_1.1.1d-0+deb10u1.dsc 1e3a91bc1f9dfce01af26026f856e064eab4c8ee0a8f457b5ae30b40b8b711f2 8845861 openssl_1.1.1d.orig.tar.gz f3fd3299a79421fffd51d35f62636b8e987dab1d3033d93a19d7685868e15395 488 openssl_1.1.1d.orig.tar.gz.asc b0cbf0a6219ddcb3ae325f321affd9614c6cf04c9ecc475f7a070be22f3e9376 84040 openssl_1.1.1d-0+deb10u1.debian.tar.xz Files: a4ab5ae8a117379e42cf5f8c85dc522e 2472 utils optional openssl_1.1.1d-0+deb10u1.dsc 3be209000dbc7e1b95bcdf47980a3baa 8845861 utils optional openssl_1.1.1d.orig.tar.gz 56a525b2d934330e1c2de3bc9b55e4e2 488 utils optional openssl_1.1.1d.orig.tar.gz.asc 48dbaa426bc352bf0a38aeb7319cbf43 84040 utils optional openssl_1.1.1d-0+deb10u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQGzBAEBCgAdFiEEV4kucFIzBRM39v3RBWQfF1cS+lsFAl2OdZYACgkQBWQfF1cS +lsYEwv/TTQvifQxW2Tx65dSq0Y3JZJ1e+E4aOg5aO76CNwJ55SA02BAW0ntdyPH z1IUFk7XvHEYdNgSlTaW7lto5zijwx6ROhUnB5Lzqlk+VrxU+u50U/SBGWSAeP2o ANLYHb9zSmpu1FOLRxlyazLado4A7rsKa2tDo39Jnr+xnQz6LzJ2X9+IzWfZ2Ig8 AUrKXXfrav7fI8FGw0vMaqRlEyy4Xc8Z8vc1w3OSzdiYbz8mIWCV+qLTd/2Nc+mI 1TYjVaU3p7Q1FWv4iRHn/8iJHLKQHuPZ/2t/7C94RMDH4YrFZ2TbvRjANf+wmdtl GKkVcpX2We4bOgPfFkRFiQZSfNSXM5/9HureFUS18LOfIpTkx3O53tTti3O+thzk 8wa4BPQpSk/W9JA08AsHVDdS1Ni3WVutUjXdOTIhzUhH7vzL54jD4uZ3EQDw0Yrg 8jUGeRKLjtzthImjNuuVfQeQ79RCuL5znpPP3OWiRkZa+suh2187WWsKV5MJ2d6t wbZITsCr =rTFA -----END PGP SIGNATURE-----