-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 17 Oct 2022 22:37:53 CEST Source: libksba Architecture: source Version: 1.3.5-2+deb10u1 Distribution: buster-security Urgency: high Maintainer: Debian GnuTLS Maintainers <pkg-gnutls-maint@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Checksums-Sha1: 065d3bd671e221d3ff5395d6dfa460c70c1e9ef6 2741 libksba_1.3.5-2+deb10u1.dsc a98385734a0c3f5b713198e8d6e6e4aeb0b76fde 620649 libksba_1.3.5.orig.tar.bz2 dc2f832fbc4ad91461e64e1684aa3933aef0d7b5 287 libksba_1.3.5.orig.tar.bz2.asc 0b1f861784dbe02184fb5c29f319ac4a4fcecc10 14344 libksba_1.3.5-2+deb10u1.debian.tar.xz 5896069727b1a35a1217265814ac689a96be7f62 7216 libksba_1.3.5-2+deb10u1_amd64.buildinfo Checksums-Sha256: c2bb7c3fc5078bf257e66db890a5ff1ed0c31bee09072ad3f75b0739e336868e 2741 libksba_1.3.5-2+deb10u1.dsc 41444fd7a6ff73a79ad9728f985e71c9ba8cd3e5e53358e70d5f066d35c1a340 620649 libksba_1.3.5.orig.tar.bz2 a954b03144ee882c838853da24fd7b6868b78df72a18c71079217d968698a76f 287 libksba_1.3.5.orig.tar.bz2.asc e1b466bf16e79d24c2addde1b96a54dd3d67be7480fbe7eeb8b3223adaf1b387 14344 libksba_1.3.5-2+deb10u1.debian.tar.xz 4b7625dd28d024efe2fb7d1278fa4eb72f51e05ebdf3447cfc4205ca33ec4ee7 7216 libksba_1.3.5-2+deb10u1_amd64.buildinfo Changes: libksba (1.3.5-2+deb10u1) buster-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix CVE-2022-3515: An integer overflow flaw was discovered in the CRL parser in libksba, an X.509 and CMS support library, which could result in denial of service or the execution of arbitrary code. Files: 91e067ef107c2631baccf02cd01e481f 2741 libs optional libksba_1.3.5-2+deb10u1.dsc 8302a3e263a7c630aa7dea7d341f07a2 620649 libs optional libksba_1.3.5.orig.tar.bz2 03829355cb173803483b2455576a4ff0 287 libs optional libksba_1.3.5.orig.tar.bz2.asc 1ba3e15c09c1ea27548d0d35b35c4418 14344 libs optional libksba_1.3.5-2+deb10u1.debian.tar.xz 8c799264416c61716077edb37867da74 7216 libs optional libksba_1.3.5-2+deb10u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmNNvUxfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkKAkQAKtECNvfW1f3kRsxRkPNz0HQw6RubGPqHbJu bratBxL/ciQNpYTCgrM/VGOqlN4Xzw2++N0xTNJPEa4XRdzhFbjFxQCg+pDi3sGO xnHwKmqdxBgVKDRmGwFCIyvvPRL7b9gNA7bKqURDDeREw3GlhwYs5/VIehdWTnJ1 wj2KjIzzVDVYGhjOrYx8KMfdPOobZmuDpOSPxHC7vVqwuPTeAxR1JeXmlkZ5mUgR yJSCJSEM7uIhQCw5/H5IBtSYsB2LLMDMdtnTYymRqzGAi8aUmu/M3iMM36eO4fcu xYopDXThkw6oBqKPjtXtNgbWcTab/gbJwvvTivxpw1ObGct+y+v/Wk2KKUSd6p4E XJzhOtbAjXNOobxbI44z4aN2MgSrId4xMm2Ie4P2xeLsKyPLTlZacoPFxUpFlWYJ M/5xBDc4CnpFK/pPyQA/9eVc3JLn6vZlUl7mwltrcljnv+avuc2HkxSUbDrDm79X SvS+vrVUOAoz1zcTpAIHNMGDM1cDZ3fnToVbDQ3oWTGghkU1RY58sJNsuVIBAKQP dJ49qi5w0Aoj8so8ybg3SjH19rpISTJdR5GISLXv5sYzb4OgurlTIuxXGWutOB2A 00K8TyTRpddX43v93Y1iSdEVbyPuDwi+lkwdZvzIcOz+GKOme8UISOi99c3E3bYf ErRbSQhm =l+2J -----END PGP SIGNATURE-----