-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 27 Oct 2024 15:16:28 +0100 Source: openssl Architecture: source Version: 3.0.15-1~deb12u1 Distribution: bookworm Urgency: medium Maintainer: Debian OpenSSL Team <pkg-openssl-devel@alioth-lists.debian.net> Changed-By: Sebastian Andrzej Siewior <sebastian@breakpoint.cc> Closes: 1074487 1085378 Changes: openssl (3.0.15-1~deb12u1) bookworm; urgency=medium . * Import 3.0.15 - CVE-2024-5535 (SSL_select_next_proto buffer overread) (Closes: #1074487). - CVE-2024-9143 (Low-level invalid GF(2^m) parameters lead to OOB memory access) (Closes: #1085378). Checksums-Sha1: 4d9249449834a193bae7531ff730d25f088a7752 2675 openssl_3.0.15-1~deb12u1.dsc cecd647994de5b6bd065d88d8c81ad30f8ac6409 15318633 openssl_3.0.15.orig.tar.gz 1800c5c002de9d0a81dc7820178b1c96869de2aa 833 openssl_3.0.15.orig.tar.gz.asc 2aaa3f6f2406ff4fe8aa1b84b69d6e2b4cb3d9b1 55220 openssl_3.0.15-1~deb12u1.debian.tar.xz Checksums-Sha256: c036907f6c634ea026143b904f8359222dabe44ef756d13e124e7e7645ef0d67 2675 openssl_3.0.15-1~deb12u1.dsc 23c666d0edf20f14249b3d8f0368acaee9ab585b09e1de82107c66e1f3ec9533 15318633 openssl_3.0.15.orig.tar.gz 781ffd542b9ec58d88333abb9af7fb8133059703f023a0b1a555086c51b2b3de 833 openssl_3.0.15.orig.tar.gz.asc c4428a53771dd15b8cb1de4a790fae23b849438bd59f853f2ac686eee7e38876 55220 openssl_3.0.15-1~deb12u1.debian.tar.xz Files: 7888338acd0fa561c8f2847f53cf82e1 2675 utils optional openssl_3.0.15-1~deb12u1.dsc 08f458c00fff496a52ef931c481045cd 15318633 utils optional openssl_3.0.15.orig.tar.gz ff2a0b40ee7d92996e6c4c8c412a3a57 833 utils optional openssl_3.0.15.orig.tar.gz.asc f6e19decabfc830fa7765f0b843a9c2f 55220 utils optional openssl_3.0.15-1~deb12u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEZCVGlf/wqkRmzBnme5boFiqM9dEFAmcenCkACgkQe5boFiqM 9dEI5RAAtY1gpHf1+igXEGZYCHIHzBRYUgeSY7Fm+sg4AkPinurUK2QBj+grtlKN Y+4Y0t1yyCH3PiuPwuuXTq64WdftuiscnGF2bNavJMx4e46Bjjjk11/rBgR/QNgh yzrbuEpYbNGnk5wkIWXi8IUAEHqoHjUhY0E0++zTic8RMAjJYlSW9fPzRo8mvdIc pw7M6kwWypCcJDEUdjAXqTGi5FW+xPsK/dBaAHjLWJHsX8tN/O+EAy+Hbj8//MGE nAvZtoiWMr/49/5ISmQT8mbGfqwIuwYn+cb8qSG/+qnMvjBaNQK1wddBtXTxFe8A UlqvxnvfxXFjb/qo1AVp4PIkr+ULwBU+YNbut8kbVsvhKTdycKhPqh7o+pG5wCyf /l//dW5U2V+x3wDZmXBBeuLwsbAh/hOX3Y6KYFoHOoNE5nSjDoSMDuLtV+UnKCTP qdDAy/ovX/HBPTfdEpbeTTMJQpwHw1RXtqGh0ZYlXRbDfNxNsW3eyG0E7m34MS6o 1Z9IxdMbCQIC2NVtjvEHIUB8ui6KKoRL/5S/oNSJFaBJBVjtGPDmTHrAbN3D2yHL qS5oIypsT3kQPT3MbLy8qeV5Ep5jmrvJB3Ddbi3mZH5TG4ZNpy/y+0h4YcgNxzgm /67nFr/jY1rjltGWiBSGbAQ2k4h8YBMQT55M3nIaqBjkA39IPxI= =swOo -----END PGP SIGNATURE-----