-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 28 Mar 2022 22:32:49 +0200 Source: golang-github-russellhaering-goxmldsig Architecture: source Version: 1.1.0-1+deb11u1 Distribution: bullseye Urgency: medium Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Closes: 968928 Changes: golang-github-russellhaering-goxmldsig (1.1.0-1+deb11u1) bullseye; urgency=medium . * CVE-2020-7711 null pointer dereference caused by crafted XML signatures (Closes: #968928) * according to ratt, nothing else has to be built Checksums-Sha1: 6b85c0111bcb81185e7cf4861f057751ee62c510 2742 golang-github-russellhaering-goxmldsig_1.1.0-1+deb11u1.dsc 676594fda7c14fe53d157fde08967ac450c5b740 3300 golang-github-russellhaering-goxmldsig_1.1.0-1+deb11u1.debian.tar.xz aff65c80c106bccceb4f314870ee4f6f858f9d7b 7146 golang-github-russellhaering-goxmldsig_1.1.0-1+deb11u1_amd64.buildinfo Checksums-Sha256: 66fbb673d17272a08184ff12cb38ee0745c0e5b8fd5b5970a32541e52260b3cf 2742 golang-github-russellhaering-goxmldsig_1.1.0-1+deb11u1.dsc cb0eed56ffadd2c5d1e1be24a24bac3174cdcfba6872a063f9a98a0f6ad5a009 3300 golang-github-russellhaering-goxmldsig_1.1.0-1+deb11u1.debian.tar.xz 045c625b9a4d6f0adfb3aa894f6e6a80a0217bbcde331b32d8913c14f0b7e4a8 7146 golang-github-russellhaering-goxmldsig_1.1.0-1+deb11u1_amd64.buildinfo Files: 1d451feb510482a33f3eb8f06c22402f 2742 devel optional golang-github-russellhaering-goxmldsig_1.1.0-1+deb11u1.dsc f42d77f7e3973370809224cb5e92be22 3300 devel optional golang-github-russellhaering-goxmldsig_1.1.0-1+deb11u1.debian.tar.xz b6799f01a2638dc9a93de76cdf5182c7 7146 devel optional golang-github-russellhaering-goxmldsig_1.1.0-1+deb11u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmKVOuFfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYR6ELD/9xz/ielIO8AffPNX/pdC5dpN5glZ93 xgCqa8aSiHzWzCYxEWaQsdy3gJCtMl7YQ+XcJEKP4t0Uy/3XW8F0A4Zqd3aY3ojC Ozbv3P5S8/Wgaf3s2SxDm0Zegc2DFhP1L1wcSX/F154D5jw2A6SnTV9f6LUeuVq3 KepYy3ba+bXp1PAq3Sl4BHM61pQ9XK3dNYsZ/n0/Pk8a2w1GSvYLEPEyDKi6JKZk hgEEphwF/5txWT2xtCoRfanA52Iz7P6KSD7OAtxVPWVMjyOvY1XfegbELAHWMyOT vY75Em8QWvrTpT/DngFhVSTF5d/PjMYHH+J8xi8wsCKvIaGTwayGkWOp1J8mDrKk 2z1MPWeHr4a5Q66eCzeDXNgABy6I+7hDv+fkyKYWNWTbMWnMzIj3GleA3AEYPec7 Brp//2GcXx3CcQPeglwdh5SU7wxbX67Xq6jXPDbDfuGAQP8s7evG2Pfz4Fh4pqYf pYgWldJyRKPJvYBrf1nF9g6VBcCrRFe1Onp+NrY86JRmRcoGYt8FCfci2JGTaMJD seulzhC12o9CqvfahICtODECYc0sRuAWRo53ZTdYLFGDrtMWGssQ1kpZGITQqo2q r9N94uKp2U4uZ+8ILXktdgyLCN0CzQvKw0RJzdYkPxkwJwPtlUrRIcDk/ukmGa0x Rka/uV4TL8sveQ== =v8yZ -----END PGP SIGNATURE-----