-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Mon, 10 Nov 2008 19:42:54 +0100 Source: gnutls26 Binary: libgnutls-dev libgnutls26 libgnutls26-dbg gnutls-bin gnutls-doc guile-gnutls Architecture: source all i386 Version: 2.4.2-2 Distribution: unstable Urgency: medium Maintainer: Debian GnuTLS Maintainers <pkg-gnutls-maint@lists.alioth.debian.org> Changed-By: Andreas Metzler <ametzler@debian.org> Description: gnutls-bin - the GNU TLS library - commandline utilities gnutls-doc - the GNU TLS library - documentation and examples guile-gnutls - the GNU TLS library - GNU Guile bindings libgnutls-dev - the GNU TLS library - development files libgnutls26 - the GNU TLS library - runtime library libgnutls26-dbg - GNU TLS library - debugger symbols Changes: gnutls26 (2.4.2-2) unstable; urgency=medium . * [CVE-2008-4989.diff] Fix man in the middle attack for certificate verification. CVE-2008-4989 GNUTLS-SA-2008-3 Checksums-Sha1: 6250ee91525bcfc0b11e7bb28bd7579c52274bd1 1545 gnutls26_2.4.2-2.dsc a64b3fd2588c43022cb6898297e414b556ead85f 15275 gnutls26_2.4.2-2.diff.gz 12c46086e8f18ceb3e73fe1d950938651b2a3c9c 2761370 gnutls-doc_2.4.2-2_all.deb 85dd7ce8d91c5baba699f5bc905180de8ac0b0e1 536882 libgnutls-dev_2.4.2-2_i386.deb 46cc130688c59bf3457162de164d13c3546c9dec 455882 libgnutls26_2.4.2-2_i386.deb bd8be58c73e25e10c50985a98990160a1b78e89c 1090494 libgnutls26-dbg_2.4.2-2_i386.deb 1dcd7776514a45bfbe812b3ab6c7c480f39aaade 268822 gnutls-bin_2.4.2-2_i386.deb 938cfe4d66f54af69f50cada1c899ffd64e887fc 210490 guile-gnutls_2.4.2-2_i386.deb Checksums-Sha256: 07c4e588d0de964c8f57953cba9db1e46c20aed01e86f116404adad6e3db4342 1545 gnutls26_2.4.2-2.dsc 03f3f81d5dc92fc226e4c6d1be25074b61f57108a710715c1060cf55819f2128 15275 gnutls26_2.4.2-2.diff.gz 7899c1b7763b82a13132596dae2f2df19a3770fabf4d905dca4c7d91e7122494 2761370 gnutls-doc_2.4.2-2_all.deb 74306d18d822fa72c798582e40092e6400b8bd996be2a9d4baabebc70f9f9a63 536882 libgnutls-dev_2.4.2-2_i386.deb aee51df092c9e381e462bb076c91fb2eff8ac6081bdf5460839ca188a0455a34 455882 libgnutls26_2.4.2-2_i386.deb bd740a57ba7db8a4832d790d63ebc0e699c116b4427097f59eb4c7348d0ff323 1090494 libgnutls26-dbg_2.4.2-2_i386.deb 94690b0776172273094c58980fe7c71f56c4e07ddbb032b2075fef6cb49a4563 268822 gnutls-bin_2.4.2-2_i386.deb 438ee8e48c10adfd8c195476c3bae303b1c19dd8ad354fa55ed892abd30770cd 210490 guile-gnutls_2.4.2-2_i386.deb Files: aab40e29b5d4432ad3d1682b548893d6 1545 devel optional gnutls26_2.4.2-2.dsc 9c32738ea1bee36e10d71effa05abf81 15275 devel optional gnutls26_2.4.2-2.diff.gz 472e3f2f9066983f8d09bc12d1f3fa84 2761370 doc optional gnutls-doc_2.4.2-2_all.deb 202db65aec39fe7e8816c9ef6546e035 536882 libdevel optional libgnutls-dev_2.4.2-2_i386.deb adee0e974fb6ee14b7c5826d800bbfe5 455882 libs important libgnutls26_2.4.2-2_i386.deb 51b4b1651d1da62c3ce95dda96914bec 1090494 devel extra libgnutls26-dbg_2.4.2-2_i386.deb 1a9a35b486a87b5a3226a62a32db3cee 268822 net optional gnutls-bin_2.4.2-2_i386.deb 3650617b8caa161a13b34bbdb7235d06 210490 libs optional guile-gnutls_2.4.2-2_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkkYhfMACgkQHTOcZYuNdmNr/QCfXBDPHIxz6F3sUWR/El/lSFJZ fuUAn1tK3eJ4qfOzQFclfpCNGAg7/llf =xANr -----END PGP SIGNATURE----- Accepted: gnutls-bin_2.4.2-2_i386.deb to pool/main/g/gnutls26/gnutls-bin_2.4.2-2_i386.deb gnutls-doc_2.4.2-2_all.deb to pool/main/g/gnutls26/gnutls-doc_2.4.2-2_all.deb gnutls26_2.4.2-2.diff.gz to pool/main/g/gnutls26/gnutls26_2.4.2-2.diff.gz gnutls26_2.4.2-2.dsc to pool/main/g/gnutls26/gnutls26_2.4.2-2.dsc guile-gnutls_2.4.2-2_i386.deb to pool/main/g/gnutls26/guile-gnutls_2.4.2-2_i386.deb libgnutls-dev_2.4.2-2_i386.deb to pool/main/g/gnutls26/libgnutls-dev_2.4.2-2_i386.deb libgnutls26-dbg_2.4.2-2_i386.deb to pool/main/g/gnutls26/libgnutls26-dbg_2.4.2-2_i386.deb libgnutls26_2.4.2-2_i386.deb to pool/main/g/gnutls26/libgnutls26_2.4.2-2_i386.deb