-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 07 Dec 2019 09:44:47 -0600 Source: python-ecdsa Binary: python-ecdsa python3-ecdsa Architecture: source Version: 0.13-2+deb9u1 Distribution: stretch-security Urgency: high Maintainer: Debian Python Modules Team <python-modules-team@lists.alioth.debian.org> Changed-By: Josue Ortega <josue@debian.org> Description: python-ecdsa - ECDSA cryptographic signature library (Python 2) python3-ecdsa - ECDSA cryptographic signature library (Python 3) Changes: python-ecdsa (0.13-2+deb9u1) stretch-security; urgency=high . * Add patch for strict error checking in DER decoding integers. Fix: - CVE-2019-14853 - CVE-2019-14859 Checksums-Sha1: 4f6719d09852ad176093b9c7138139af19fb843e 2274 python-ecdsa_0.13-2+deb9u1.dsc 7bcf6d1773d08bcc4bdd28cd05c545969f5aa162 55579 python-ecdsa_0.13.orig.tar.gz 720ad3832e1d2b4de3b530110b9b653ac7b2c966 6560 python-ecdsa_0.13-2+deb9u1.debian.tar.xz bf9e3ffbeae2ba5ad46adc004ac3e41f5e5410ae 6361 python-ecdsa_0.13-2+deb9u1_source.buildinfo Checksums-Sha256: 81ffa934c7977f42cba0e4272fd872adc985cee9fe93652b7bfb412ea64a49d7 2274 python-ecdsa_0.13-2+deb9u1.dsc 64cf1ee26d1cde3c73c6d7d107f835fed7c6a2904aef9eac223d57ad800c43fa 55579 python-ecdsa_0.13.orig.tar.gz 082566e70b16cb2158ba16511d532494d5e7487683690dd94db43b303e3760ca 6560 python-ecdsa_0.13-2+deb9u1.debian.tar.xz 3f3bca1806d21567e0fe0cdc6f483f31a8e1917aefc3490c3a62e3cd17aeaacf 6361 python-ecdsa_0.13-2+deb9u1_source.buildinfo Files: 39845a3d725c8797e2cb677ea920ba8f 2274 python optional python-ecdsa_0.13-2+deb9u1.dsc 1f60eda9cb5c46722856db41a3ae6670 55579 python optional python-ecdsa_0.13.orig.tar.gz 0fb77aaf89bb64581f8ccdbc16231710 6560 python optional python-ecdsa_0.13-2+deb9u1.debian.tar.xz 10c393183680d4d344237a99a2ed3523 6361 python optional python-ecdsa_0.13-2+deb9u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJFBAEBCAAvFiEEdzOzKNJ5X1viMlrdAVCdXKtK/T8FAl3ydlMRHGpvc3VlQGRl Ymlhbi5vcmcACgkQAVCdXKtK/T+4aA//XIws6ikSJWJaE1qWZd0xjdimC2bZxZRL 31o57BzXI4iEZVs3lUcZTNO7Jc2V13rXUQ3+IBCo3xPNku1yBXW15+yH5VzLpxIz deQ8W8hNkexK61d1B/oCyXCAV5YlHwED+yw9NXyUR8SRF1+WTO1ry278cEVZcRpe 0vNhS3gbNGgGVhQTUsWrIKUBhYzJ9eZJaLRojBtoBq1Xz49K98HFadVDIyHchkF7 b18KSGUP+PF6XQNr1GosoBQ5DDYH2e8eVzX7teYNQuLffYdLouTyk26gQtRXoHjm 2serPkAHxLCifnuwCsqsqMB/ZVSV+qmBzTx40TcilsNoQkop0dvaGK4obSue9idZ fYvgeIbhY0r7LjTCokW77eysQYRI/b/nFoGaMDO00fxCaJ5/vR/BqLc6HHHQufFb fEcW/alO+6cDwjB0fNe14H9AQZukv1/ev/bIxNJa688YzvJ7oG6tSCI0DDlEAE0T osUTnb4UkwQ3xZY1wOSsx90FkplxJ4MN0wzobjgNJNfhtK7QAy4eRiMya5pME2s9 pMt8/7w6cHRJzMZan9NaOSHT3ggLC6RSSaZlUh6/05+7g4oexsBzFqamtdhJyN/D t31tbRW4PYcA5sHa/R+HvtTXl5Jzny/gl9iZEYWV+1IJXUlJOfKo1wBp3REeZ0QE aWGITRxW4pY= =3A40 -----END PGP SIGNATURE-----