-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 16 Mar 2021 15:06:43 +0100 Source: tor Architecture: source Version: 0.3.5.14-1 Distribution: buster-security Urgency: high Maintainer: Peter Palfrader <weasel@debian.org> Changed-By: Peter Palfrader <weasel@debian.org> Changes: tor (0.3.5.14-1) buster-security; urgency=high . * New upstream version, fixes two security issues: - Disable the dump_desc() function. (TROVE-2021-001 and CVE-2021-28089). - Fix a bug in appending detached signatures. (TROVE-2021-002 and CVE-2021-28090) Checksums-Sha1: d21d37c8b54de43aa0290fe1e0a2de14490fd823 1968 tor_0.3.5.14-1.dsc ff7fde50edf96ed0fb5a5872cff1d3fa468a3b7d 7115630 tor_0.3.5.14.orig.tar.gz c2a258e10336aad70d3fab93670b9b2cf8623f31 51064 tor_0.3.5.14-1.diff.gz Checksums-Sha256: a8828b7f13ebe1ae8a652aa27b2b2017745b58cf6060acd526694bca3153e430 1968 tor_0.3.5.14-1.dsc 3b8668bdd4b973b7ccdd5bd5bc47f5a79cec0845c8349a0d9defaffe8621e485 7115630 tor_0.3.5.14.orig.tar.gz 09de19e7aa6986b2387b26ffac39683a139299275c7b7e177dd5bc2d4e6ff644 51064 tor_0.3.5.14-1.diff.gz Files: fef178ed223e3d72cc56ae3d7ec7cfca 1968 net optional tor_0.3.5.14-1.dsc 95996b38a9c1d0cf6482ae08abbd33bf 7115630 net optional tor_0.3.5.14.orig.tar.gz aea84e7e2c587d0415d050eb2c4869bd 51064 net optional tor_0.3.5.14-1.diff.gz -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEEZI5W7zrm8w5X0SHVIw/UyqaI+y8FAmBQvqoACgkQIw/UyqaI +y8LQwgAkCTTaWnPMabqkS+8BJHbDlkCnn/nxfNSmbknORW2ZtU41arpwHZZMvxQ QOvK3LxNDAdxaMsjz+dY8WN0P9d9cSFpypLm9gRT/WyIfmmFP67sZyv//DF5YkS0 ykHAlXOjGyKS6Co+AGTZezJvboxBTfO63ReT6pFWcpNgug6RLefcXl20w8Cfr4nR 6wWvHJQXyBAbZVtuEvkUYnrt7wtGPELW4j7Y/szhV8rIhBlickSBjRaIATMP4/xr NIcCYnVXqHD9vgpfgoyrc00iloRGcvHjx9L6d4Dt2yHNTZR0Rc8HTDb/qyqYijgi j8iPo0bYgiB5USu6Xly1PVrvkidzDw== =jCiU -----END PGP SIGNATURE-----