-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Thu, 20 Nov 2014 14:46:05 +0100 Source: libgcrypt11 Binary: libgcrypt11-doc libgcrypt11-dev libgcrypt11-dbg libgcrypt11 Architecture: source all amd64 Version: 1.4.5-2+squeeze2 Distribution: squeeze-lts Urgency: medium Maintainer: Debian GnuTLS Maintainers <pkg-gnutls-maint@lists.alioth.debian.org> Changed-By: Raphaël Hertzog <hertzog@debian.org> Description: libgcrypt11 - LGPL Crypto library - runtime library libgcrypt11-dbg - LGPL Crypto library - debugger files libgcrypt11-dev - LGPL Crypto library - development files libgcrypt11-doc - LGPL Crypto library - documentation Changes: libgcrypt11 (1.4.5-2+squeeze2) squeeze-lts; urgency=medium . * Non-maintainer upload by the Debian LTS team. * Add 37_Replace-deliberate-division-by-zero-with-_gcry_divid.patch patch. Replace deliberate division by zero with _gcry_divide_by_zero. * Add 38_CVE-2014-5270.patch patch. CVE-2014-5270: side-channel attack on Elgamal encryption subkeys. Cryptanalysis attack as described by Genkin, Pipman and Tromer. See <http://www.cs.tau.ac.il/~tromer/handsoff/> * Both patches have been backported from the 1.5.0-5+deb7u2 wheezy security update. Checksums-Sha1: 701c218a570c2bd0bda3dd89cb0617e7a6c173f4 1943 libgcrypt11_1.4.5-2+squeeze2.dsc 1eb6d59ea000b1ad9627131b6c4023ebbef6d26e 19740 libgcrypt11_1.4.5-2+squeeze2.debian.tar.gz 789eb7eebeaa06de0739709590860f67b44f5a9c 670850 libgcrypt11-doc_1.4.5-2+squeeze2_all.deb 1197943131f95b3f3a66abef553a9b797dfa5db5 383166 libgcrypt11-dev_1.4.5-2+squeeze2_amd64.deb db9f1cafa88ef9abec04e27286a07d06979261b7 350290 libgcrypt11-dbg_1.4.5-2+squeeze2_amd64.deb f714b0433c155ff97426377a4a06eea951b2a67d 282974 libgcrypt11_1.4.5-2+squeeze2_amd64.deb Checksums-Sha256: d50c720a728a79ea4206cc3d4d0298714b8a3071aa06fd428a7429098e81eb98 1943 libgcrypt11_1.4.5-2+squeeze2.dsc a825f1df80b642843997b20dab691210b4dce318a2245cd1d431116aa9339b5a 19740 libgcrypt11_1.4.5-2+squeeze2.debian.tar.gz 5b5c023df603e5d83da33a87892d092e7d8879960e4e5100473098536efe6016 670850 libgcrypt11-doc_1.4.5-2+squeeze2_all.deb 6621cb85678a62db01706c56b558756fcc1c6338eefabb27f6c14ca125c6f89d 383166 libgcrypt11-dev_1.4.5-2+squeeze2_amd64.deb 1f810e1e828554782212b5e19564db022b68c4adc95a29dcbd4e9bf9307e5f96 350290 libgcrypt11-dbg_1.4.5-2+squeeze2_amd64.deb 538e1b575ce938ce68af37b72c9fc2af63d3010978e913c0ea23789ccaaaee7c 282974 libgcrypt11_1.4.5-2+squeeze2_amd64.deb Files: d69cb10727fe763d496eab73c795c113 1943 libs optional libgcrypt11_1.4.5-2+squeeze2.dsc 47b104642f17fd576dc3428a63e596e2 19740 libs optional libgcrypt11_1.4.5-2+squeeze2.debian.tar.gz 9c1d32a14719f029e5a6c9283fb20b45 670850 doc optional libgcrypt11-doc_1.4.5-2+squeeze2_all.deb 1e338f8ac204f1d04e18b7c6cfa21ca5 383166 libdevel optional libgcrypt11-dev_1.4.5-2+squeeze2_amd64.deb 2b27c20579b01e662ddef44495335a00 350290 debug extra libgcrypt11-dbg_1.4.5-2+squeeze2_amd64.deb 560a8e1dc4716c5bf5d040c01acba1d5 282974 libs standard libgcrypt11_1.4.5-2+squeeze2_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.14 (GNU/Linux) Comment: Signed by Raphael Hertzog iQEcBAEBAgAGBQJUbfrZAAoJEAOIHavrwpq5QOIH/1bwh6Q1dVTwh5UhQrKKnUJI aFzb90hJlMItDA/4Hlz4FeyIjJi4MSAMiKN1pErf+aE424APrxVvyn4Yf570HyQ5 Y+TQn7QIBrY1LUaWo5WAjtjxiNZAyG2qf3UJugIg1vg9xJRQ8b9hYecFAw0s9viU SiaJ6KER6whZr6djSIvQQG5wDuIhk1YrGdfA8ibg+XC8mRTRtN1ebytvgrWF1M0G gmKTMVsDbb3zgvhLwpxc+TkwnOzNCN8fB0XxcXFbB8Zm1/WUHHodZtxtmXEWekK4 8XNIPRUgGfmXJUqa3lbDCU5RHPvoWEvPZuHg1bS+ZjrUcV/k3OZbwVwTDK/Pv1Q= =1gDu -----END PGP SIGNATURE-----