-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 23 Mar 2024 11:11:34 +0100 Source: gnutls28 Architecture: source Version: 3.8.4-1 Distribution: experimental Urgency: medium Maintainer: Debian GnuTLS Maintainers <pkg-gnutls-maint@lists.alioth.debian.org> Changed-By: Andreas Metzler <ametzler@debian.org> Changes: gnutls28 (3.8.4-1) experimental; urgency=medium . * New upstream version. + Fix side-channel in the deterministic ECDSA. Reported by George Pantelakis (#1516). [GNUTLS-SA-2023-12-04, CVSS: medium] [CVE-2024-28834] + libgnutls: Fixed a bug where certtool crashed when verifying a certificate chain with more than 16 certificates. Reported by William Woodruff (#1525) and yixiangzhike (#1527). [GNUTLS-SA-2024-01-23, CVSS: medium] [CVE-2024-28835] + Update copyright info. + Update symbol file. Checksums-Sha1: e1d126861f81813e5280840205f4eff7657f3261 3271 gnutls28_3.8.4-1.dsc 2a2d0183918ed7050b308e0307ba15c177c38705 6487520 gnutls28_3.8.4.orig.tar.xz 3cc654ee2f0264a2c5a34d8a12fea171fa54150a 228 gnutls28_3.8.4.orig.tar.xz.asc 6564a913ed26185c7aaf8cdb11a9a746e3ecda73 77056 gnutls28_3.8.4-1.debian.tar.xz Checksums-Sha256: 6e73fe12193d5b7fff869b258f592cf85e03d7a94c1739cda28e08c9bb65351d 3271 gnutls28_3.8.4-1.dsc 2bea4e154794f3f00180fa2a5c51fe8b005ac7a31cd58bd44cdfa7f36ebc3a9b 6487520 gnutls28_3.8.4.orig.tar.xz d776e9a0794539e44107c20b5a2f9126c62833e3c0206eb682bd240fff41558a 228 gnutls28_3.8.4.orig.tar.xz.asc 89816d3e88ed35c424d92f5bb0fe4aa13bd37a575890f807826468533320695e 77056 gnutls28_3.8.4-1.debian.tar.xz Files: f012ccc6c1c54051833f53699e4b5eb7 3271 libs optional gnutls28_3.8.4-1.dsc f6ba9454115a82deb352c4336648490f 6487520 libs optional gnutls28_3.8.4.orig.tar.xz f51f08d94837877194adc97c9cdae1e7 228 libs optional gnutls28_3.8.4.orig.tar.xz.asc 27361e355b7707846527bba421c3132d 77056 libs optional gnutls28_3.8.4-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0uCSA5741Jbt9PpepU8BhUOCFIQFAmX+wnwACgkQpU8BhUOC FIQp9A//QJx7PS2NqiwOKAotpR0FOebJAIurQHZ/TDGygChyHSc5NJ3C9I72v2KS hAUQQGa2ol/XYlBhq/CyCiLHurtm4LnnmTx4UleZfsSToQfkNE+yZZ7xwgsQbvEG IPfldSgjtu9qN6gJ+CddHqQDQuLsDnaJjl6lR9E1AuS0I9r87F8LC3bmDlxu7s5c 5IPhZ5EUjIdmXGh4IUDFV9CWgkrC34hhA9ZUrefVk231EA4eYr9mfWhIoTbWMVjr Z7Wpd0X0nC1o2Z1tOkt4V4wbuzVbcXh2JZpK7ZWQoWQLBJt7SJrT77CIC3hjkpwN 8zyCM27RM5G77MT5IYavrIsZmNjE+oSwVJg+bnUlD31ULIoxwwpUKsXxuppHnN0I elXefOdsrjKj1iSzB1XlKAMunfUewKz5oooAEyrPwnn4orpqXvjLWOvfPxEUJtyA hsuyOrapiRPG/PMC5C5dUniCNXYpJRsodKJkkq/3DDPIRGoF4YWCuhf6pIvDmKuN aQ+wbo8lvp2ExxVh3xwFW+5V+hkGpGqyDj0yc+9rHLAE6hUMfgpX8lqmrJ+SDj09 DmLwYV8Wjz+yXO/nJJf3A4jwjeidFYVu3r8/yPeXgmgCidky8BcsfELuTXGYzr07 JRmlVYrjb+IsXP44rD+NqeYKDUmyEmtKxeAgsYI/NZB8mD9Szd0= =SKal -----END PGP SIGNATURE-----