-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 27 Mar 2022 18:32:49 +0200 Source: golang-github-russellhaering-goxmldsig Architecture: source Version: 0.0~git20170911.b7efc62-1+deb10u1 Distribution: buster Urgency: medium Maintainer: Debian Go Packaging Team <pkg-go-maintainers@lists.alioth.debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Closes: 968928 Changes: golang-github-russellhaering-goxmldsig (0.0~git20170911.b7efc62-1+deb10u1) buster; urgency=medium . * CVE-2020-7711 null pointer dereference caused by crafted XML signatures (Closes: #968928 * according to ratt, nothing else has to be built Checksums-Sha1: 56d03316cefbecaf4355c54509dced42e23ad641 2845 golang-github-russellhaering-goxmldsig_0.0~git20170911.b7efc62-1+deb10u1.dsc c4c3980900ca84670d82dc4a7ccd9547223fd423 6924 golang-github-russellhaering-goxmldsig_0.0~git20170911.b7efc62-1+deb10u1.debian.tar.xz 6cfc39f35cc49dcddacca009628df640c5617000 6876 golang-github-russellhaering-goxmldsig_0.0~git20170911.b7efc62-1+deb10u1_amd64.buildinfo Checksums-Sha256: a7874d8762bf1c419b1fcfa5834a5a1af710f963bf0d5caada431a3e353c0e21 2845 golang-github-russellhaering-goxmldsig_0.0~git20170911.b7efc62-1+deb10u1.dsc c2ab81a4bbde0a612600e39efd3f5bace2561ea392170e4989b1eac5b1d41a86 6924 golang-github-russellhaering-goxmldsig_0.0~git20170911.b7efc62-1+deb10u1.debian.tar.xz 836622c4981c9928ed993569cad021c719c5c1f7bbc84b0de827f71dec12449d 6876 golang-github-russellhaering-goxmldsig_0.0~git20170911.b7efc62-1+deb10u1_amd64.buildinfo Files: 4a7a235bf901724497a4c87f10d3b4ba 2845 devel extra golang-github-russellhaering-goxmldsig_0.0~git20170911.b7efc62-1+deb10u1.dsc 9bf1aabe6d0bf0641e5d545524e71ab2 6924 devel extra golang-github-russellhaering-goxmldsig_0.0~git20170911.b7efc62-1+deb10u1.debian.tar.xz 60138378ae6bf781e701f2e050e4b9fa 6876 devel extra golang-github-russellhaering-goxmldsig_0.0~git20170911.b7efc62-1+deb10u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmLtq/1fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYR5eqD/sHx1PdwwUPnjfGk22KAzp57GuTOkCh Tw/ElmzlV1Uyb/H8lE+wNW57YZDQvb03xWX/ugnVjbLm6+JjrQhAQ5feTFKNZijv YcqPVEMq7mcd2bqytluFFQb0aCbVd0EyR1gjsZ9hc32il0nSKyNU7eNtwpjiPfes FBO8uIOyFuBixtMCQFhs99yKvJWEOVh9a/5DltPiOr+2yGWnWMS1IE/xnP4I0JfX m6gyPrJTMJVSXyfbPt/ig02sDqH2ZjqwALjQ0Z/OaQuFe+CcPSwYH1e3LzS3wlxs mcs4JT2WwriDPbh9q8bQYiIDjOk1a8iXTl1lG/96DnUe3ISnOYMH4MYoG1ZwjANT OGfdCT5uk6N1p9QJWjJtPDeFAgC95Qf/t3as1NkaYo1tr043OClCgSlUBEwxqE07 uR+eTfn99uXhlSvZ8ZBMeW0QTitdiEqBwVR3x2rj8L9J5V12xfYw3qqLLpjcoDiS /E2jIdqDMUqWYzA8tB2cMhc3M8LIQuS30G6ZNF1rm5nxGFlkFe4pdfWquhlqk3zN kQ1dtVJzULQJfwQs2l7nCoB5/jUHLh2gHKlvTWKmYpZ57YYAFzuPI3+dhAf2A9uO GrLpDeloysO5mK9W3VSmYZVvsWu+75NezlOEj2Y9E4QjOgx1n440eaPQ7hRfUtHa D1Pbd1VkUGJiFA== =74Ob -----END PGP SIGNATURE-----