-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 10 Aug 2021 01:54:10 +0200 Source: lynx Architecture: source Version: 2.8.9rel.1-3+deb10u1 Distribution: buster-security Urgency: high Maintainer: Debian Lynx Packaging Team <pkg-lynx-maint@lists.alioth.debian.org> Changed-By: Axel Beckert <abe@debian.org> Closes: 991971 Changes: lynx (2.8.9rel.1-3+deb10u1) buster-security; urgency=high . * Apply fix from Lynx 2.9.0dev.9 for CVE-2021-38165 to fix leakage of username and password in the TLS 1.2 SNI Extension if username and password were given in the URL, i.e. as https://user:pass@example.org/ (Closes: #991971) Checksums-Sha1: f8c7f55657011b3a391a4b2a03bab682e3f7497f 2560 lynx_2.8.9rel.1-3+deb10u1.dsc 3e00ac30d008e0aa879bfd037abcfd9c0dd2faec 2689171 lynx_2.8.9rel.1.orig.tar.bz2 60ad87a45201396c291931d86411f35a8a4af97f 251 lynx_2.8.9rel.1.orig.tar.bz2.asc e2f097c682aa263db6b72094ebc60f17e0c06811 29404 lynx_2.8.9rel.1-3+deb10u1.debian.tar.xz 4e3a35e0dbb518150f6890c33fde4ba77ea63566 7143 lynx_2.8.9rel.1-3+deb10u1_source.buildinfo Checksums-Sha256: bbab09e6482a4f433fc6063cc34f0353882b9fb4dfc10c8987959e58db00b312 2560 lynx_2.8.9rel.1-3+deb10u1.dsc 387f193d7792f9cfada14c60b0e5c0bff18f227d9257a39483e14fa1aaf79595 2689171 lynx_2.8.9rel.1.orig.tar.bz2 2cb6cf09763d58ec6951bc0bf4cf2836983756fb168f486d30f0a3921304408b 251 lynx_2.8.9rel.1.orig.tar.bz2.asc 0578691571d26b702748845e0acf2436e04b9c75b9e7d643465c23a1170bb8f4 29404 lynx_2.8.9rel.1-3+deb10u1.debian.tar.xz fb0a2488cc3ad65e194f2fd9a74d74a6c517deac5808a72b9631c8001ee762d2 7143 lynx_2.8.9rel.1-3+deb10u1_source.buildinfo Files: ac5876d02e4878400ebbea60e6481107 2560 web optional lynx_2.8.9rel.1-3+deb10u1.dsc 44316f1b8a857b59099927edc26bef79 2689171 web optional lynx_2.8.9rel.1.orig.tar.bz2 d0cd3214b950926ddfc88a7c6d35cec8 251 web optional lynx_2.8.9rel.1.orig.tar.bz2.asc e45c95752470dc4a06b9d9e4f0e865f6 29404 web optional lynx_2.8.9rel.1-3+deb10u1.debian.tar.xz 12020315232c68b3b4e1b58948e4ffb0 7143 web optional lynx_2.8.9rel.1-3+deb10u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEERoyJeTtCmBnp12Ema+Zjx1o1yXUFAmERzU8ACgkQa+Zjx1o1 yXV+Eg/9HZMmVHM0424x4CN8idgGlTD82sO9Ht/5yyaa5TAkstQ35WS488Gr2SKU GRUPiRQG3RIQ/1ae9hWKCB+BvQuhLkafFFoxiuQ+I5Z/scmyPkYqcc4IUgBgla/i e+Q/zMhN62BxJyGKNRWR2Vty52dtOSlmkUFd/klynNGFehghLBWFSxnTRLbx3aer EshAoW+MlnxbLoDMzCP4jfePzz6UWi/uG5LjZZ4N5GWzd4H6tEn4nwpkxOT2T/uy 9XqBaCwG7tIw34eZ3hgBRIHawV6aXvgeZPUAqI+unrbzeH2COkrTjhlem1ra1w+n 9HxbIyDlvKIuYMqjgL3kRQtUTHV9XA1/s0HgKmSOdiuEynm/ofvWhhIYdi+1AYQ/ E0zEFwVgQmPfGXzlnt0moFNWm+f5NijdHd//1vfUsH5RQCBn63FW+IfenTlzra6j Q6n0NogzRu8nCdePrnstGRe2SXQUdzpGJjdNTTmZiW8DGqcwKy7OwgLkp+pqTJQq Y3ruCsi37qaueAGI2RFU0WLvvOuqa2obF+APblzVcUeuLk5krL8ZDfk8cOP77Y7z OTz6Lk+faDir9i782Zo2hg/bDXSMiSlrgNMhkQqW8684yRCzb2jCg4JapK73CcXs ezXZ2PQYL8fm51sAIbBtskE/N0kQa/yBmg6t3zlio2pI/la8t4I= =okwX -----END PGP SIGNATURE-----