-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 01 Jun 2017 21:04:22 +0200 Source: strongswan Binary: strongswan libstrongswan strongswan-dbg strongswan-starter strongswan-ikev1 strongswan-ikev2 strongswan-nm Architecture: source all amd64 Version: 4.5.2-1.5+deb7u9 Distribution: wheezy-security Urgency: medium Maintainer: Rene Mayrhofer <rmayr@debian.org> Changed-By: Yves-Alexis Perez <corsac@debian.org> Description: libstrongswan - strongSwan utility and crypto library strongswan - IPsec VPN solution metapackage strongswan-dbg - strongSwan library and binaries - debugging symbols strongswan-ikev1 - strongSwan Internet Key Exchange (v1) daemon strongswan-ikev2 - strongSwan Internet Key Exchange (v2) daemon strongswan-nm - strongSwan plugin to interact with NetworkManager strongswan-starter - strongSwan daemon starter and configuration file parser Changes: strongswan (4.5.2-1.5+deb7u9) wheezy-security; urgency=medium . * debian/patches: - CVE-2017-9022_insufficient_input_validation_gmp_plugin added, fix insufficient input validation in gmp plugin which could lead to denial of service (CVE-2017-9022). - CVE-2017-9023_incorrect_handling_of_choice_types_in_asn1_parser added, fix incorrect handling of CHOICE types in ASN.1 parser and x509 plugin whch could lead to an infinite loop and a denial of service (CVE-2017-9023). Checksums-Sha1: 18a0faa2a5c61f189833c2d6eef9b685d6340e87 2195 strongswan_4.5.2-1.5+deb7u9.dsc 16768242efb6cf7ad5c6b32c98ed28c3a003a69e 152332 strongswan_4.5.2-1.5+deb7u9.debian.tar.gz 9220a1b70f1bd672affecad928998aba0f383ad9 81842 strongswan_4.5.2-1.5+deb7u9_all.deb 75fc1c5c00f7b339f9c9e12ecb452b889519471e 519944 libstrongswan_4.5.2-1.5+deb7u9_amd64.deb bfd4b6a6202562853c8fdb443d30d4aab728ed02 198670 strongswan-dbg_4.5.2-1.5+deb7u9_amd64.deb 29116f4caa447eb2ff6598cc167e1185e3720d41 316404 strongswan-starter_4.5.2-1.5+deb7u9_amd64.deb b1feb27bdf96fb1761dce8aaa5dd2afb73c26dfc 345888 strongswan-ikev1_4.5.2-1.5+deb7u9_amd64.deb e81bc4e07bdefff904b7c470ec47712ee6a28eb6 387424 strongswan-ikev2_4.5.2-1.5+deb7u9_amd64.deb 53603bfc622760811de64109156573b6130bf076 58736 strongswan-nm_4.5.2-1.5+deb7u9_amd64.deb Checksums-Sha256: 598e2f5257244b4ae7a387c21c6e80ab78baeb9d62ecefe586824429997ed5a6 2195 strongswan_4.5.2-1.5+deb7u9.dsc 76280eafbb5c5e390bce9e77d0a97fbf2cb2f2ede1d82ba4059ace08f27453ba 152332 strongswan_4.5.2-1.5+deb7u9.debian.tar.gz 4dded2c29ae81ebdea274915b716c3a10ad5a4072ca0ea90c3d631d26556f3f5 81842 strongswan_4.5.2-1.5+deb7u9_all.deb afe47a051d4139033b0e64551924a5cdf4cbef59bb66903022d49babe881c349 519944 libstrongswan_4.5.2-1.5+deb7u9_amd64.deb f5166255129386a0a47f4be6782c76672ac52d0b4ea8aa01457aad64b2946a7e 198670 strongswan-dbg_4.5.2-1.5+deb7u9_amd64.deb 0b72db163e96180248ac2f511adcb7151fb6d309138c651fe32478971917ac3f 316404 strongswan-starter_4.5.2-1.5+deb7u9_amd64.deb d17cda7e6a02a50b8021d6b78535a00678af5eed19c37462f78fd14396a0761c 345888 strongswan-ikev1_4.5.2-1.5+deb7u9_amd64.deb caa0c521439c87942ee53919438a32d9e72d1289d08f8ee774d0d777f84ab784 387424 strongswan-ikev2_4.5.2-1.5+deb7u9_amd64.deb 9516d0addb1b0cd454a6a09b5080a4191dfcaa5a84a4d78fa6dfd7c8136440a4 58736 strongswan-nm_4.5.2-1.5+deb7u9_amd64.deb Files: bad2040bba86ebbd38734ba93618e10c 2195 net optional strongswan_4.5.2-1.5+deb7u9.dsc dd49e4eb3452b57e7f6145720a4af4e7 152332 net optional strongswan_4.5.2-1.5+deb7u9.debian.tar.gz b782b70cc0ac3904a08b5e370d6c027f 81842 net optional strongswan_4.5.2-1.5+deb7u9_all.deb c29850b991bc239c2dac68df6f5576b9 519944 net optional libstrongswan_4.5.2-1.5+deb7u9_amd64.deb 6dcecc9bece79a87009dd193203eedba 198670 debug extra strongswan-dbg_4.5.2-1.5+deb7u9_amd64.deb 9217faf3148dae9dec0d3e34ec4ee692 316404 net optional strongswan-starter_4.5.2-1.5+deb7u9_amd64.deb d9719509bd011332a389a79a405724e6 345888 net optional strongswan-ikev1_4.5.2-1.5+deb7u9_amd64.deb b0304dbe191bd73c66838dc7713ef464 387424 net optional strongswan-ikev2_4.5.2-1.5+deb7u9_amd64.deb 66acf3bb068e2b494c186d2067cdf730 58736 net optional strongswan-nm_4.5.2-1.5+deb7u9_amd64.deb -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEEl0WwInMjgf6efq/1bdtT8qZ1wKUFAlkwabUACgkQbdtT8qZ1 wKVsIwf8Dd7pdchTCcGNfTSzmgCugwIqltkXwaISkFzaIor43ChjGT/jaZseSeXO Ed3qbKhmLSHlHimDGalWd8sihG+3NpW7iIRU1lRya6p9DnCkN6nvQnzc7gSHme6g YiX7fQ0IeTPaXB1/t78Q5yPUm8SVosiYHT73O3BbkXf5fGhHBMAKFETM/jNYf9lH ySANfdoGfOk9zapxuEYFAJx7Mpq5zCeg88EQ0AP63vPmDzOLTKost6p8gVkyrj29 EX3uYsYhMz7U4DvOknhouIzUH5p4W2Rm1TbaWYKNlnYDxt6deSua8sD/kLsF1irC Dgils1DcwXZBKVNmYG6jI72ah0RTEw== =JzvF -----END PGP SIGNATURE-----