-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 10 Nov 2014 19:29:30 +0100 Source: gnutls28 Binary: libgnutls28-dev libgnutls-deb0-28 libgnutls28-dbg gnutls-bin gnutls-doc guile-gnutls libgnutlsxx28 libgnutls-openssl27 Architecture: source i386 all Version: 3.3.10-1 Distribution: experimental Urgency: medium Maintainer: Debian GnuTLS Maintainers <pkg-gnutls-maint@lists.alioth.debian.org> Changed-By: Andreas Metzler <ametzler@debian.org> Description: gnutls-bin - GNU TLS library - commandline utilities gnutls-doc - GNU TLS library - documentation and examples guile-gnutls - GNU TLS library - GNU Guile bindings libgnutls-deb0-28 - GNU TLS library - main runtime library libgnutls-openssl27 - GNU TLS library - OpenSSL wrapper libgnutls28-dbg - GNU TLS library - debugger symbols libgnutls28-dev - GNU TLS library - development files libgnutlsxx28 - GNU TLS library - C++ runtime library Changes: gnutls28 (3.3.10-1) experimental; urgency=medium . * debian/rules: fix pattern for removal (and re-generation) of autogen-ed manpages. * New upstream version. + Includes fix for a denial of service issue CVE-2014-8564 / GNUTLS-SA-2014-5. + When gnutls_global_init() is called for a second time, it will check whether the /dev/urandom fd kept is still open and matches the original one. That behavior works around issues with servers that close all file descriptors. This should take care of #760476. Checksums-Sha1: e2948e5807af2666ca8706a19367d306e415d01e 2920 gnutls28_3.3.10-1.dsc b47af4ee116ba2099a24ff7a8e686079f80ec23a 6173572 gnutls28_3.3.10.orig.tar.xz 5392ffa081889bb3a9258a975670f4729f81b196 83156 gnutls28_3.3.10-1.debian.tar.xz 303598238822d95e03c85576debab0d50dbab167 686594 libgnutls28-dev_3.3.10-1_i386.deb ba499b11d95cdc2c9fbe05a813fa6ef246aba9bb 715974 libgnutls-deb0-28_3.3.10-1_i386.deb b2e2e523e7957e80c378199413c81e490520671e 1932386 libgnutls28-dbg_3.3.10-1_i386.deb 57362f3f86fc91abe163a17e69a84e1099685fc1 315832 gnutls-bin_3.3.10-1_i386.deb 6749d420011a467564c6f44d363d52bee9bad6fa 3636974 gnutls-doc_3.3.10-1_all.deb afa388a149debee490bfe83e7413580da1df6216 179952 guile-gnutls_3.3.10-1_i386.deb a031f8cc994ebfd65cc1d4ddbcd38213f9631efd 15404 libgnutlsxx28_3.3.10-1_i386.deb 531b51d5e1034b59f5bfdf4b3b30b1809ff2f14b 146862 libgnutls-openssl27_3.3.10-1_i386.deb Checksums-Sha256: ad103f1a4e1adddb7939b6a8ed95b80b724885f047045ec164b38754318e227e 2920 gnutls28_3.3.10-1.dsc e27553981d48d9211a7e5e94f6e78c575205202a181c2345a1c8466ebf1d2219 6173572 gnutls28_3.3.10.orig.tar.xz 92a389c10cd9ffca4d6fae6c9a57e82c384948072e956e84693ea71b759f077d 83156 gnutls28_3.3.10-1.debian.tar.xz 1851f4e8be04955168a90d5fe41bb7e227b3639bc2e3e3522f4e428c8a9d1c60 686594 libgnutls28-dev_3.3.10-1_i386.deb bbce38af43ffb88683b6c6bcdc1c3ad19964538c56ba6724580aa6d1586d9ccc 715974 libgnutls-deb0-28_3.3.10-1_i386.deb 14d4458c48a73103af3478e488652a2267c15d5eb22bcd524c64e95151b9e23c 1932386 libgnutls28-dbg_3.3.10-1_i386.deb 925f28ada36dc05433b190844692db7cee7f9c9dba20d96899d9664b2c4b18c6 315832 gnutls-bin_3.3.10-1_i386.deb 429a3b796b4dd0a4897c63f3f6ac61bc469de88f55a7fddc8ba0fce1e1eda7b2 3636974 gnutls-doc_3.3.10-1_all.deb e4b8a703b7a657ed525ad37cf041184371f42d9749e7070aad75b8ff5fdc5312 179952 guile-gnutls_3.3.10-1_i386.deb bd593fc35af4cef9bdbff4ca15fcf0901e73406de4218d31d66ef9598ad5286d 15404 libgnutlsxx28_3.3.10-1_i386.deb 2f68d0419bc761749260b37108cdf26d88a3f09c0f2c5556d9f18b16cffd2c96 146862 libgnutls-openssl27_3.3.10-1_i386.deb Files: 045e08afecf1f86f8eb6c842e91cc56b 2920 libs optional gnutls28_3.3.10-1.dsc c0a72b2c0553fe1c4992e30835808012 6173572 libs optional gnutls28_3.3.10.orig.tar.xz 20bd39a85c28927df1fce8e39610c1a1 83156 libs optional gnutls28_3.3.10-1.debian.tar.xz f1b32d5c7aa51c6374a8906039c0506c 686594 libdevel optional libgnutls28-dev_3.3.10-1_i386.deb c7f09a6df60258341bfd73e5ca3ed9ef 715974 libs standard libgnutls-deb0-28_3.3.10-1_i386.deb a72e07525b4d5b2e502583096c5e2b6c 1932386 debug extra libgnutls28-dbg_3.3.10-1_i386.deb 8b88a119b7c7ab5d4f354e92d73eea52 315832 net optional gnutls-bin_3.3.10-1_i386.deb e9c3e2fb8a8fc39c7074cded01374848 3636974 doc optional gnutls-doc_3.3.10-1_all.deb e04f1ec60071df6b400b0c1092b81f97 179952 lisp optional guile-gnutls_3.3.10-1_i386.deb 24a42f5c45b07a68fbca3f2de12e131b 15404 libs extra libgnutlsxx28_3.3.10-1_i386.deb e2511dc4522784bfc9c1f70d62a13060 146862 libs standard libgnutls-openssl27_3.3.10-1_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJUYQdMAAoJEKVPAYVDghSE10oQAJeVBCaACCQ1yWrEcIek37dk 8xDavS/TSpZ5UuAElqBBkJ2CVQsY8+vFRti8muP68zBCU8TOC0TimipfAbxDCocu aBV9F+te6SmZIWEvdy7E5oeB88S8Sq0W8DhJV/oi6sTxOJbu2lmW6bUxV4OBBneQ 28FN7vur7aG8ZL3znAWA5Azw/H98hdNgICQBFRmqAzMOEXlfiAryH8b8lbCa1b7p XsHMtD5KLroAZkmgWtPniLan3gFpK6SmdRq3KQGnN4QeaTPTZqvbKCtcLheDuVpR 5rkrUDMubJLmxSn9ld2cizFh6fyF6W2p39xyWx7WzRQbSSuHYa8sc45Z/ThJvWHX UQVwacOhZ3+Xd3qlviBWSE1gS/gai+cGamDNPKO6mqvS886vmnxhMvQdjJ8DQYOQ u27v+BQz9iqVsCexXOEgSdWl5I5WmTY8xQdWmazgamVYtS2aTQ1MJrnt3RHQOChk GK0yrRqbfNapEZtcwYhlp8Pz8VsBBcgvDS8spGRZjvKZ+01vCT0J+96td+x+x/8o t16HZj2w8z1eJWtTy0X79+Nq1s9JXCWsPU8WVbI14m6tlzZAQ39zqTIb+cLPR9o5 cy2d3TSTFpopz4ieC+bgEgTYHfXRBSlpMfX5d075So+95KejUKr9AyxlzRcKf5pA ZwtiEtpHNZgNRwZEvDTd =U/gk -----END PGP SIGNATURE-----