-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 06 Sep 2016 22:56:10 +0200 Source: libtomcrypt Binary: libtomcrypt-dev libtomcrypt0 Architecture: source amd64 Version: 1.17-3.2+deb7u1 Distribution: wheezy-security Urgency: high Maintainer: Michael Stapelberg <michael@stapelberg.de> Changed-By: Jonas Meurer <mejo@debian.org> Description: libtomcrypt-dev - static library, header files and documentation for libtomcrypt libtomcrypt0 - public domain open source cryptographic toolkit Changes: libtomcrypt (1.17-3.2+deb7u1) wheezy-security; urgency=high . * Non-maintainer upload by the LTS Team. * Backport fix for CVE-2016-6129 from upstream git commit 5eb9743410ce4657e9d54fef26a2ee31a1b5dd09: an implementation flaw in the RSA signature verification at src/pk/rsa/rsa_verify_hash.c made libtomcrypt vulnerable to the Bleichenbacher signature attack. Checksums-Sha1: 2f2f04a329aead7647f9270c2553bdcaee97a4b8 1829 libtomcrypt_1.17-3.2+deb7u1.dsc 8de54fc139d078d8da73303e8907e9a2f9254f7a 1721194 libtomcrypt_1.17.orig.tar.gz fb4bd46d5da4f61a327c56909d1da6253252d7a5 4663 libtomcrypt_1.17-3.2+deb7u1.diff.gz c295dfbc205539dc33fab619b7a84d89196916a9 1229270 libtomcrypt-dev_1.17-3.2+deb7u1_amd64.deb 70c05953f903700b05c8fa215cc6001187162fe6 403372 libtomcrypt0_1.17-3.2+deb7u1_amd64.deb Checksums-Sha256: c62cf293c8dd2ec4ccbebb6e17da0a97c315b28a900f4c7f75a0f0f5094c21a0 1829 libtomcrypt_1.17-3.2+deb7u1.dsc 23be62bf7598ea210b7d2ea6f31edd8ab7dbcbcf28a887e2bfe030cb3e22b14e 1721194 libtomcrypt_1.17.orig.tar.gz 30fe581317333993e23cada324360e80aca580c0d54c10f2cd92218fd5bc3b85 4663 libtomcrypt_1.17-3.2+deb7u1.diff.gz bed43e66559c3fd4496ef3c628aada04d50e6381ab625f0370535385fd793cc2 1229270 libtomcrypt-dev_1.17-3.2+deb7u1_amd64.deb 5cb4ca270d494a98c122c3b9e83319fed98c036569d05ce5aae99874e6236929 403372 libtomcrypt0_1.17-3.2+deb7u1_amd64.deb Files: 32684063572b5c8e89baaa7485585fef 1829 libs extra libtomcrypt_1.17-3.2+deb7u1.dsc 1996612d56e9c8e631193cb51492a911 1721194 libs extra libtomcrypt_1.17.orig.tar.gz 6e15bfcdfec7fd973b7be74f049d7b61 4663 libs extra libtomcrypt_1.17-3.2+deb7u1.diff.gz dee0c512935288590fbfd8ca2cdc7d37 1229270 libdevel extra libtomcrypt-dev_1.17-3.2+deb7u1_amd64.deb e2c8db3af3b61ed0252124e6004868e1 403372 libs extra libtomcrypt0_1.17-3.2+deb7u1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJXzzEuAAoJEFJi5/9JEEn+ZhsP/0PyQ4qd51YZB4j9sKesjQTd s2s5OQN5kKHcrzyyaw/Lz5WqWHl9H+404O59n9v4F+5NerUc2zJopHmjikxSnCcj fj3Hge6xIpB3/Mj6wsCvlB75cH3I7AZyG1n+vXSKcOlgPyB9hEM/lHhLnn8pufMp PIGwi8SgMu5XyrjbOaJcrqLEViPKRkERf19lK/PvUCi2LJbAB+ytFHraJPdYgv0U hN7eSD91Ibaxcg0bDbxUClq5dT8dgDT7T28+GImJclJPcA0lQ9O5vYpDHqqXU3wE +xlih/843VmuFHJoRtp/c9AOw7f0qenTyOgymcp8Br4hs0KO5e1SoS0/ACrcpftR +xDOSDl2Oa3XXTacxv6GN2bbAP/7dpj9cDtieTiovKqVDtciNNIYnWRQ9NVDngfe H7ZUIULSGKDajZKoXZvjuuEh3gtg1AS1AE83qKKUB13YIvXn6ihnG0FpPgZLIXxh a2u3Kw0ubZ6sLJgKobtYV/kdwMZxn2QNUVnp1pBFAUMVVK+fgG3Nx9e6KxBY/OYu 6LMIbogpKEctNT5/4JGclHI4WO4MErWFmiMbXzKm/xoesKtE5dHPFplKNS77E2zS wEfjen7nIzOYsJ3asbtkpIBskOvukE4h06EMr85L5IuoOry9JvAr0Jb9WigVt/nj JHwIAkYwyVRMQkTkEY96 =G1Ky -----END PGP SIGNATURE-----