-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sun, 02 Jul 2017 22:37:35 +0200 Source: openvpn Binary: openvpn Architecture: source amd64 Version: 2.4.0-6+deb9u1~bpo8+1 Distribution: jessie-backports Urgency: high Maintainer: Alberto Gonzalez Iniesta <agi@inittab.org> Changed-By: Bernhard Schmidt <berni@debian.org> Description: openvpn - virtual private network daemon Closes: 865480 Changes: openvpn (2.4.0-6+deb9u1~bpo8+1) jessie-backports; urgency=high . * Rebuild for jessie-backports. - change build-dep: libssl1.0-dev to libssl-dev . openvpn (2.4.0-6+deb9u1) stretch-security; urgency=high . * SECURITY UPDATE: (Closes: #865480) - CVE-2017-7508.patch. Fix remotely-triggerable ASSERT() on malformed IPv6 packet. - CVE-2017-7520.patch. Prevent two kinds of stack buffer OOB reads and a crash for invalid input data. - CVE-2017-7521.patch. Fix potential double-free in --x509-alt-username. - CVE-2017-7521bis.patch. Fix remote-triggerable memory leaks. Checksums-Sha1: 7f33288b8d5d270e4e1f6ac4b12966900e118ce4 2145 openvpn_2.4.0-6+deb9u1~bpo8+1.dsc 5d09a2655c89cc85cfb00c65af8fb64507f9d223 60504 openvpn_2.4.0-6+deb9u1~bpo8+1.debian.tar.xz 07cc8744aed535de45da9deff8cd7fa798f6a621 576396 openvpn_2.4.0-6+deb9u1~bpo8+1_amd64.deb Checksums-Sha256: cae1421a0c91bff32d1db9f483bbde23c33d2c6cc6c6c969845a34c494633c9e 2145 openvpn_2.4.0-6+deb9u1~bpo8+1.dsc bf9cc597b3c44a2ce33ac6d0e9cf63b4fb3163c1d30bf5b861c25b263b18cdd4 60504 openvpn_2.4.0-6+deb9u1~bpo8+1.debian.tar.xz 1a08d36b8d357983afc4bfc270274f59fd6eff3eb8daf3542b3b77565657b35f 576396 openvpn_2.4.0-6+deb9u1~bpo8+1_amd64.deb Files: c983ce75e433968170a60728b49f4677 2145 net optional openvpn_2.4.0-6+deb9u1~bpo8+1.dsc 366f748b70f8aaf3047ec3ebf0ba8aa8 60504 net optional openvpn_2.4.0-6+deb9u1~bpo8+1.debian.tar.xz 607430388a5d7eda2466d65c4c9a31ee 576396 net optional openvpn_2.4.0-6+deb9u1~bpo8+1_amd64.deb -----BEGIN PGP SIGNATURE----- iQJFBAEBCAAvFiEE1uAexRal3873GVbTd1B55bhQvJMFAllaocURHGJlcm5pQGRl Ymlhbi5vcmcACgkQd1B55bhQvJN5hg/9FiZPZNpRZut354E03znxX0KSrfB9ttq0 ZSraE0PIbXSa5QdU/o5i5yWQBqooVVVUBzgw67P1ooFwFyel6s3mypKswFRO6Oox IR1uYwMQj26rEnClii5Ix2ca/xR6Zylvv7byQs/fb4iFuauZUWG/74H/t+QfRG4F ndzE42ZOzmgd3xGPsWQNnccGKd1iuXTlwEav4YPttZmQz7qhuM1LhujUGEukz7K0 sbYguqF2qjAfSKnmkTc/XA0SCEm7jo3HqicItTqL+ha45zylLMVgqidfeACgy0N7 ivcZNirA5ifY98YQPLcaWo/F1srVIlnBXTb0vzs1l1zgvQQrMJG7i1PR47dTEkqv U9KLbSMJzMGS7HhE3DqX0i4Zme08pEdiAuvQkiGPOEpqRKeW6NaBD1wf9OdiES+/ f1VEpYeqOJHDCdykmlT1nBuln1T1AQvZl8ZtB/P4Pt0SVeoCQJdNjb4f01FRjIcu G652V3Skm+pCnx/Iv8Xj+GELgghPioqzsHfhNdMdypskn3QuyJkAtOheDVMZwtn+ KQJxnE5BDsTtrKcXK7+AEnN2jAariSJpFzIgp4zJQIEog473VaoBQEzOo4UF6hal kCe8qeRRd1XpnX5EkJeWRlLgmv7q3njxbdPrLjExmQwzOuwrhs1phBjIC/YGqRDs LKo0EkWT72M= =kntT -----END PGP SIGNATURE-----