-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 23 May 2017 19:01:02 +0200 Source: libtasn1-3 Binary: libtasn1-3-dev libtasn1-3-dbg libtasn1-3 libtasn1-3-bin Architecture: source amd64 Version: 2.13-2+deb7u4 Distribution: wheezy-security Urgency: high Maintainer: Debian GnuTLS Maintainers <pkg-gnutls-maint@lists.alioth.debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Description: libtasn1-3 - Manage ASN.1 structures (runtime) libtasn1-3-bin - Manage ASN.1 structures (binaries) libtasn1-3-dbg - Manage ASN.1 structures (debugging symbols) libtasn1-3-dev - Manage ASN.1 structures (development) Changes: libtasn1-3 (2.13-2+deb7u4) wheezy-security; urgency=high . * Non-maintainer upload by the Wheezy LTS Team. * CVE-2017-6891 two errors in the "asn1_find_node()" function (lib/parser_aux.c) can be exploited to cause a stacked-based buffer overflow. Checksums-Sha1: c64a8e6142ba607a0d0b74505dec9709f581455c 2492 libtasn1-3_2.13-2+deb7u4.dsc 89120584bfedd244dab92df99e955a174c481851 1964659 libtasn1-3_2.13.orig.tar.gz 898ff64bab791f7a873a2f77752b7569a41ca1a2 13459 libtasn1-3_2.13-2+deb7u4.debian.tar.gz 0f2ae65c5bd8ee7c82dd31627ae3845cecfd76ef 389976 libtasn1-3-dev_2.13-2+deb7u4_amd64.deb ea88dfb533c4d26f8173fd596a20f71be47a5dba 153490 libtasn1-3-dbg_2.13-2+deb7u4_amd64.deb 4e61f4bdc9857cb688f8be2e6c834e9a0dbbba0d 68666 libtasn1-3_2.13-2+deb7u4_amd64.deb 2891e4d06059288f772eab6fc437a49eda63b071 53742 libtasn1-3-bin_2.13-2+deb7u4_amd64.deb Checksums-Sha256: d8996334d749ff35c0e0d1880deeef7ffa9aeaa18f95aa1c4e06ca71841bbb07 2492 libtasn1-3_2.13-2+deb7u4.dsc a56e46483d1d42fe44ba58c9758620844042468d7c2d75f6318cdf3222745a91 1964659 libtasn1-3_2.13.orig.tar.gz f9609704ed1d44e6375c6857d6393a5b8546e7a561651893c68f2a4e6c681bed 13459 libtasn1-3_2.13-2+deb7u4.debian.tar.gz 2943b70954b660b23e2313991a88d73f16d4e05d1d83b0bc152df622c5e9717a 389976 libtasn1-3-dev_2.13-2+deb7u4_amd64.deb 68460f4c52446adc21e72cb8ae07eb073605d3664d6144f0779fa1c4fbc4642c 153490 libtasn1-3-dbg_2.13-2+deb7u4_amd64.deb 3260fe8508fe6d27c8ac7ce8b4b2b0accc824b17914b586c69ef5bec36d5faf7 68666 libtasn1-3_2.13-2+deb7u4_amd64.deb da67b9df91f71719051ffbb4a1bb8b781ef981319c2b4a06efdc01e9360e000e 53742 libtasn1-3-bin_2.13-2+deb7u4_amd64.deb Files: 1e17ea71569fe63b309ed41b24d2caec 2492 libs standard libtasn1-3_2.13-2+deb7u4.dsc df27eaddcc46172377e6b907e33ddc83 1964659 libs standard libtasn1-3_2.13.orig.tar.gz 74b312c39c84ab4dac573b160e2f10b2 13459 libs standard libtasn1-3_2.13-2+deb7u4.debian.tar.gz 94b0da7d34e038c8b3becb37024dc8bd 389976 libdevel optional libtasn1-3-dev_2.13-2+deb7u4_amd64.deb cc1cce72e43decb38534594b3214da1f 153490 debug extra libtasn1-3-dbg_2.13-2+deb7u4_amd64.deb 275825c0aa875dd0f540b314f99aeec2 68666 libs standard libtasn1-3_2.13-2+deb7u4_amd64.deb 6a24d2457de9d875311219077907b8ed 53742 devel extra libtasn1-3-bin_2.13-2+deb7u4_amd64.deb -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAlkkbc9fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYR0LsEADHeWoUIV4t8zXaqBHx7kanUtqeZUrO yv/eAVnZ3Vb739x2i1hnbUPwOV4RwbTBATUlQFA5oHjxdjYFkm63WTPSOGUqOt8S 5QlBOqXuVquvmlebgGTN4qAH7qDLheU4J37ZUnyW2Ju7aQE5+OzpfmWdbR4GYMzy 4g29mp1+GrZU8W4SVKbsrIEJLGFfiTga+SOd332bxVyrXcWfl49VGDFaJrDa8c7y dU3inOkFynhY/YGp3KNk8XApZHLtsZFvRopok+hWCTP37XNVGtTFKSQEv3UX6808 CBtAF/qV0NJvZFiJvGdYnwQyu+m50fuEydD+jqVsEEVMFgn62TZ3T7pu5xQWUzKx OnsrIbuEFcf57kBbchqs7xu0d8RVhhhP7eYo1vpe80Tl14lDT3tzYPB5CEeBXBCO KJiplRuAP+eTn+vt9srWPIM+E+1t3zIrskccHo9RFPJz8kExHYhXze59+7r+RGsH o9evpxcfSmqmJuLyeSv+jxVLHzwbP+E421XI/RmTxQTOPZLGXDFgDtprolIIFTA8 gS/OdBtr6+Lib7L3hw8RgT5KSUhMUmXaEsFBzQSJwguyr5/d/4j7AJA238tKA+6Y gp6HcPjYuPa6fVhmoGKs0DnK2R5JJNAdAF0VQ/E6MaTYTj6TWb6a9eH9GzOu4Wwj Q2j33xJ5MJtxWw== =yBmO -----END PGP SIGNATURE-----