-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 14 Oct 2021 20:17:07 +0200 Source: strongswan Architecture: source Version: 5.7.2-1+deb10u1 Distribution: buster-security Urgency: medium Maintainer: strongSwan Maintainers <pkg-swan-devel@lists.alioth.debian.org> Changed-By: Yves-Alexis Perez <corsac@debian.org> Changes: strongswan (5.7.2-1+deb10u1) buster-security; urgency=medium . * Reject RSASSA-PSS params with negative salt length - fix remote denial of service (CVE-2021-41990) * Prevent crash due to integer overflow / sign change - fix remote denial of service (CVE-2021-41991) * d/gbp.conf: track buster-security branches Checksums-Sha1: 4212416e491d9b49e7be0a7813859fb2eac53af9 2928 strongswan_5.7.2-1+deb10u1.dsc 307d4d7c7d5cf6e904b85ec735cb8eefc33bb9c2 4997818 strongswan_5.7.2.orig.tar.bz2 21dc1e6c83f4979a0a693ad752bdeaf5b5eb498e 116812 strongswan_5.7.2-1+deb10u1.debian.tar.xz 778e56cfc8a1cc31f2f4f26432fc05e5fdeba108 16942 strongswan_5.7.2-1+deb10u1_amd64.buildinfo Checksums-Sha256: a9283e330fa612edf9fcb3d3998f159359e8eadabecacf3f0b2440a70588a652 2928 strongswan_5.7.2-1+deb10u1.dsc 308e3ba76e2ce2da070e48fcebbe1fa923a27cc71e43bf63917e6f2a889ecc70 4997818 strongswan_5.7.2.orig.tar.bz2 99070cc1233509d93682162f65f4a0d83ca0cf24194d9bb9b8b4166cc53a4ae2 116812 strongswan_5.7.2-1+deb10u1.debian.tar.xz f8667ab50f0cea4edd3194150ab672485ff7654c8088bed885212e72222187a7 16942 strongswan_5.7.2-1+deb10u1_amd64.buildinfo Files: 6c6ceab40e8d9bebebd7bb10d6bd2b45 2928 net optional strongswan_5.7.2-1+deb10u1.dsc 618de96dc2a506f82a162a5abf9263d4 4997818 net optional strongswan_5.7.2.orig.tar.bz2 4a17d87d933a84de501d684a1f0d3b18 116812 net optional strongswan_5.7.2-1+deb10u1.debian.tar.xz 9b9688fe87d6aa30b68e20b0474b8616 16942 net optional strongswan_5.7.2-1+deb10u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEE8vi34Qgfo83x35gF3rYcyPpXRFsFAmFpnpwACgkQ3rYcyPpX RFt1mggAkRp67+fd4STMWEHW4gCAy5B/jzeiTS30MPx7l/sc4W2NlMUG68kpui9+ tUpXHiVm8pqxBszrwgom2T/elhw1BlOZJ65nGK4JcJjWGdExOsWXGoUKPpwhRTMa hc5idF0Y1fzzxfVelaq7diEIFhlAnGgtupNITrVcEGITY5qx+Fwd7rIScp5RJnjr 47zCJ8qPqT17tS4WyVqon/vBEWGbmgER9juBPRZZsAAErjZ3sdY9YhZyruDRofwC cwVOq30ONibn5wGMZS/dHfusg+7YKiNsIVC4Dhg6jNZR8wSVaP9ewgluTWdy6eLM nDg1kkbG+8Sz11MRYgIYk7pwG/WL/g== =NgZV -----END PGP SIGNATURE-----