-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 21 Oct 2019 17:36:37 -0600 Source: python-ecdsa Architecture: source Version: 0.13-3+deb10u1 Distribution: buster-security Urgency: high Maintainer: Debian Python Modules Team <python-modules-team@lists.alioth.debian.org> Changed-By: Josue Ortega <josue@debian.org> Changes: python-ecdsa (0.13-3+deb10u1) buster-security; urgency=high . * Add patch for strict error checking in DER decoding integers. Fix: - CVE-2019-14853 - CVE-2019-14859 * Add python{3}-pytest as Build Dependency Checksums-Sha1: 25fb7e3f7db4ba07331b5a71e732c66fb9f9bbae 2274 python-ecdsa_0.13-3+deb10u1.dsc 7bcf6d1773d08bcc4bdd28cd05c545969f5aa162 55579 python-ecdsa_0.13.orig.tar.gz 9183dbb48b0ff49223401028e3942ff1194d27ff 9628 python-ecdsa_0.13-3+deb10u1.debian.tar.xz 031254ab1f7b0c8954b60ef60b15d03248647d72 6547 python-ecdsa_0.13-3+deb10u1_source.buildinfo Checksums-Sha256: aa657d5582208b2ebafe4c44790d73dcfecf14c11e2f03f72014da4432d26146 2274 python-ecdsa_0.13-3+deb10u1.dsc 64cf1ee26d1cde3c73c6d7d107f835fed7c6a2904aef9eac223d57ad800c43fa 55579 python-ecdsa_0.13.orig.tar.gz 77793b3f63942be4bb0ad4ce5afab49fa3147ae59d76acc2f19196d7d1bf1a20 9628 python-ecdsa_0.13-3+deb10u1.debian.tar.xz a696745195e992d25c47bf72222eb462b38e47dfc3b98fc5540c2bbfe06310ac 6547 python-ecdsa_0.13-3+deb10u1_source.buildinfo Files: 8a1d14e93bf302bd0c7379ffcf5c467d 2274 python optional python-ecdsa_0.13-3+deb10u1.dsc 1f60eda9cb5c46722856db41a3ae6670 55579 python optional python-ecdsa_0.13.orig.tar.gz c0d1f2a5bc13e7547f67b60ef2f62d73 9628 python optional python-ecdsa_0.13-3+deb10u1.debian.tar.xz 4c81ebffa8035246c8988d3da63bf2c1 6547 python optional python-ecdsa_0.13-3+deb10u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJFBAEBCgAvFiEEdzOzKNJ5X1viMlrdAVCdXKtK/T8FAl3IiecRHGpvc3VlQGRl Ymlhbi5vcmcACgkQAVCdXKtK/T+Y8g/9Gpt+6s19Q3G1kgmkXI64EmbSrZjuLjZk JgFhpt41vybyQ21Ua2E4lsOgSvA0pWdyxGzbUQbXcPHYOf1MRaILEQZKz1XMc5Gv z4xxtudg4KI39T79V0bwoBtOnXkqmabo1ttxoZsuoMmrVbJoL1dWBeQOSNET3FKM Bvb1iu/4R6pAnBpHt7gHTgK3Skzb23V5omRFn0hgOwokEkqScSnltY7aRREY4c0l MDhw1KiLlAlEmYsxMlL0Bln2w/WBYR5R1xoCAtlzMcdjh2oI0iI7J2O9ybDQ6OGm ObvCkIC6tONptw+lKTPZwh9IE/WCx/Bg5ol0qX1Neb5w5sYlUcUZ1ZhHwV+JWAAm YmurTdt/POzgr+TA3fiEvQWqdCZAvOFqZI5IC4uT1qXHS7Prs4xMs6ot5FUA3MP3 fEPVeg4xibDDLymdZiHaMzcpJCsRZdCv2gKvJiIXDvMp7mmebA5aZFMJt/YSiCXy pv80VpGOsHJFCyKEXHKgv8O4TIs4X8+g6e+uV/kmictAPystqky5JK+7SjIGjCD9 d6kPyFxWFPQyIBesajhaSZKR+l1BaTjhOLTJIpIFYqtZeOI8R7ibLUpUUiXZ6Row Z/H3aCFAjx5FJeI3QLZvXxFVnI7wnN2ay2MDPZQPR5iKWNC+ILAPM2O/QLJgbX+l iQ7scUKaidU= =S6pi -----END PGP SIGNATURE-----