-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 29 Jan 2020 14:34:22 -0500 Source: opensmtpd Architecture: source Version: 6.0.2p1-2+deb9u2 Distribution: stretch-security Urgency: high Maintainer: Ryan Kavanagh <rak@debian.org> Changed-By: Ryan Kavanagh <rak@debian.org> Changes: opensmtpd (6.0.2p1-2+deb9u2) stretch-security; urgency=high . * Fix following vulnerability, 018_smtpd_tls.patch.sig: smtpd can crash on opportunistic TLS downgrade, causing a denial of service. Checksums-Sha1: 3a768e5db32e31bc5ceeff3ae04c0afdbebcc34a 3096 opensmtpd_6.0.2p1-2+deb9u2.dsc 386e1115c5cbe91f67ce0854594197846b4bb5d9 695513 opensmtpd_6.0.2p1.orig.tar.gz 93f4bbb92690eb1589c360049b4ae89f16392231 26196 opensmtpd_6.0.2p1-2+deb9u2.debian.tar.xz 35c792d5e02dc7c9f545e305ce76ef59466c163d 8446 opensmtpd_6.0.2p1-2+deb9u2_source.buildinfo Checksums-Sha256: daf60a5af3cc8199a70c528894e6edaf78d6e4c65d2fa9b89ea03e87c3fa5656 3096 opensmtpd_6.0.2p1-2+deb9u2.dsc 2af9b6d08784c7e546bf124bb61e311a6aa0c9835507710a76f5c242383190ac 695513 opensmtpd_6.0.2p1.orig.tar.gz 467834ac6980f9f86f42c2765637b6d7f91ade14bdc4827110caab00c36f3cb9 26196 opensmtpd_6.0.2p1-2+deb9u2.debian.tar.xz f6bc7862ffa9975249192b524c1e6591cdddaf6fc50b03b69f7456da2bec4c55 8446 opensmtpd_6.0.2p1-2+deb9u2_source.buildinfo Files: 310faf76b7ca8b4622961b4fe625dd59 3096 mail extra opensmtpd_6.0.2p1-2+deb9u2.dsc 1ebc232624f2e2e31010c810ea0a3b88 695513 mail extra opensmtpd_6.0.2p1.orig.tar.gz 7e6942d8c9154e3f951cf16a6cdeddcc 26196 mail extra opensmtpd_6.0.2p1-2+deb9u2.debian.tar.xz 845a370e0c191855e4152e704830e3c8 8446 mail extra opensmtpd_6.0.2p1-2+deb9u2_source.buildinfo -----BEGIN PGP SIGNATURE----- iQVDBAEBCgAtFiEETkaVGe1ndzQmj72Vj3v4/EoRyXoFAl4x4b8PHHJha0BkZWJp YW4ub3JnAAoJEI97+PxKEcl6MMMn/2CahxrKxq5n96Lri9qT5/RCxm0laHkPSPve D4ckUw0sewsaExfg3cnXADBYv9PRs/+f3fVaQp6a8w6sHWU3f9vHSFHwYFyoe6nX IdtfV331C4kDI0dkRmysTdjzFg96f68h7FgnQ9jAJuGV9B6AJiZxzMUe8Dh9UquF aAxaLaXfhEXwOZZZ92SHmp35RC/Mq6Kh99D5DS0Ybz3abtl/vRaHkBee2vTKkxpL LE/mKCQGW+5gEggJHSAG0aErM9kL4u7GOW8UW4jDMwDtXhxLvJyHXK4bNcbr2+kX sy+dhtwFfjY7aax8JEBQCJtrXckClzMxLUQODn/z6VavxWTZZZwsO1YmNhZZljYh wdNgupqEnoMXU9BISGtTfLENCnB5hcd+nTY6Yu45tpy82qZy762xfJIykJ+DdxtK 1V33yzaBDtywinQL0hBeU2jhLHoDLohhhYJ0TjbuEEIMMXxLN0TG4ycCr9qUC6RD 9Q9GMXOV1+SyZH/V6Zs8c1vYgnOrDXzvsRv797OeLWoXijjAheY8HtlOlOjo3slv 653ggt7h+Pn4M409kFV997zLUrqZphJu2vrHSkNKFTVusqYDAPE6WATWAGK9cgl0 8Ka66Hz0Zx8cyW+d8z1ncasfpef4Azmjxi3roCuuBiH51N96EuCmE2DIw4ZdYutU pnbvugGZ/R0W8NgLv0gwObTqT7p52ungW5nqJXD/LjOdM1J4jnvyXJx7Lb4Ytnic QOxO1Ii3np76PNiq+w+GpWhZRZ1nu2IGETyKEQbODeIrbn3RuATkHD36CuiIOhE7 2rDqAUSEt+aRq7E+5763blgH0g+Z8yKg1av0Gb0YlmJ7i9QLKd+huNxlJYDrf/zZ B70i2iSv73ys1e4PI1rMqPTFUY9pkesrqYwO0lC/uHFo03Ch6/Rvh1tYWHhTO86o +/vOKGoOVkuI2GJgBW75EGKFcmFN9p63UY+QFXNRSQ2UYReTiLEFXlxvqdEaawRD YZ+z2X36NB99GW3abqIV/Gl7bRORydHcgzLyEDDE9B3eYb8zRXOYvFHdLnlLj51g vwIIjXWE22IVcrqRttUk7MpANwAtYkYJoP32yKhQ6ah3jyHRcASUDjfoVMFSa63m PKQfpskcaJa6ZBvyOeTIFPiYaRIarOLW9uB+t+08mN2BLTVSTIb47YeJIM6K+PVR xFpmFpqZF9AgNLxQLYqjcvkUy4KlQzPSimKaBaH8BvrPbHIP6F4Mw9rra47B9Qyr es/Pfl3IRgHgLsJYhWfRQ8MkszvDQtCHo8GodnSuCSRb5YR+tJNKe0S71iwHDENK tAFs49QXp3r31Jte3zh7imhgyR3ZC9H6rqTZUl8ExBHBGIZkFXHig0alD7vwDAVE jfWjIAhF4iOYsZJSIC6ug/A7UVpp7g0U4DKdSwlluFVCrEVq+Rhurzj8aQawi++S DhKk2TcLY0F0bn0G/dk5WV1Ph3P7V3FiZWED5h7wi9WgXA3ll31y+gELAzKRcnH0 GkcSpLy3dRIb+9rTfjIuuafK8s8eey7ocmlM81AWNhpIY6n3lNGPFbkJ4Z0AYWIZ ILwtqVTAb4UA2aOxzxUteHUZQzLesEpTGdfByEZiJMcrpQy97zNGQE7PLVlMHp+b UsyobSMJNbKzY+5OUmuix4h1UolAM0zMD7HnYPWltk6PLZDzI+yNbLOC9K5OG5rC gZExJ93z =hIam -----END PGP SIGNATURE-----