-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA384 Format: 1.8 Date: Sat, 09 Nov 2019 19:27:34 -0800 Source: wolfssl Architecture: source Version: 4.2.0+dfsg-3 Distribution: unstable Urgency: medium Maintainer: Felix Lechner <felix.lechner@lease-up.com> Changed-By: Felix Lechner <felix.lechner@lease-up.com> Changes: wolfssl (4.2.0+dfsg-3) unstable; urgency=medium . * Cherry-pick commit 52f28bd5 from upstream. Fixes CVE-2019-18840. "one-byte heap-based buffer overflow inside the DecodedCert structure in GetName in wolfcrypt/src/asn.c" Checksums-Sha1: 0e84cc6e050bbcb2ab48390a23cfe4a055c21461 1859 wolfssl_4.2.0+dfsg-3.dsc 6930b66b5311e7fb97cbeddb7a65933c58b86e58 3589600 wolfssl_4.2.0+dfsg.orig.tar.xz d2aab628b16e95a26fd186fcc24e5fab6611cc4f 20208 wolfssl_4.2.0+dfsg-3.debian.tar.xz 722022969d1c30df0f158cd41f65cf94d4e9f00c 6071 wolfssl_4.2.0+dfsg-3_amd64.buildinfo Checksums-Sha256: ebb43af69412dd11b6fa319da3e833e83ea7029fb89629c18d9301ae9c363666 1859 wolfssl_4.2.0+dfsg-3.dsc a18bca03c556e48841d3d25a61f866fa8ef986c281d52c32c8218b4667130a3f 3589600 wolfssl_4.2.0+dfsg.orig.tar.xz 7178cdfc86ea8112773dc2051cf1d63bb110a2cfbc5cdcf561b334e5591be671 20208 wolfssl_4.2.0+dfsg-3.debian.tar.xz 74e2c127923b0305696e3577bed7a5f3a550fdf88c208166072d176ea03cb8a5 6071 wolfssl_4.2.0+dfsg-3_amd64.buildinfo Files: 5eca42e16039e7ec94d9aa7b4ad99641 1859 libs optional wolfssl_4.2.0+dfsg-3.dsc 4eabdd26dc3bd342e329ae66e755cddf 3589600 libs optional wolfssl_4.2.0+dfsg.orig.tar.xz 8dcbe949bb9fefeaa473a1111a4ea01b 20208 libs optional wolfssl_4.2.0+dfsg-3.debian.tar.xz 711b6f5472ab177de0959be3427b1331 6071 libs optional wolfssl_4.2.0+dfsg-3_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCQAdFiEEjbPlhoZdK0orGFpcUAHhsJqjdEsFAl3Hi94ACgkQUAHhsJqj dEsZ9hAA31dhDVt7A8xqOW6h+rAke25Yh++/5iniVcaU/pHVwNS2fGwIvUCksdKx PWACEB1JqP9NIMxyM/civ9sJ17joLnVVOHhQ05/e6xzR+G9FKb07X+A9giL5lfQ4 1PAlOJS1iEPgIypYRUZcVmnFy4aktxMYAkjD4NNoyTSqYNV4aSglXpxeygSv2J9f jlq/NKmwO+oeic9eRJSgDAv4cumPdX2PEdPbgPRStd5RzE3DApI2E/tK/4KTTaSh cAjyTMNd5OvfEr4SwxvnY4+cURh3uIQeUE4pNwGwpwqj8ZzPawG02TwbLrZASzzQ mj3XoE1/YS8BlH08HqPIjgzpk8EBEmT0sFGd7UW3rXvAoy10G1qQ9d7XzvciaNsB T/mJMpu9+F4HduIBkv7sklVA+0E/i2O2Vx/ANQIeBGMhq2NNY2rWUspQjHcwGALp X3loIq8Hnce10xb/MjCmQjlOROcx1fufwZXs1Ju0IR/22hLee6eqMZcrWTCfTHCH aeQQDXePV5DRmRkt3jh488ccuJjqlJ1ygG1vBYebWb6m0H3uhnEmfpBABszsFEz+ KVLhPbkk1hCv7xg3N+k9yWhqCo+Qc4h+uBffhT/PePzZzqaP6KJJ4ZKh7oiL1zr2 fO0AOntONPSdRlRHB9wJE9vePrl5bq9KjxUMYhQBSt7ebji3jq0= =b57Z -----END PGP SIGNATURE-----