-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 01 Jul 2017 11:53:07 +0200 Source: libgcrypt20 Binary: libgcrypt20-doc libgcrypt20-dev libgcrypt20-dbg libgcrypt20 libgcrypt20-udeb libgcrypt11-dev Architecture: all source Version: 1.6.3-2+deb8u4 Distribution: jessie-security Urgency: high Maintainer: Debian GnuTLS Maintainers <pkg-gnutls-maint@lists.alioth.debian.org> Changed-By: Andreas Metzler <ametzler@debian.org> Description: libgcrypt11-dev - transitional libgcrypt11-dev package libgcrypt20-dbg - LGPL Crypto library - debugger files libgcrypt20-dev - LGPL Crypto library - development files libgcrypt20-doc - LGPL Crypto library - documentation libgcrypt20 - LGPL Crypto library - runtime library libgcrypt20-udeb - LGPL Crypto library - runtime library (udeb) Changes: libgcrypt20 (1.6.3-2+deb8u4) jessie-security; urgency=high . * 22_CVE-2017-752*.patch from upstream 1.7.8 release: Mitigate a flush+reload side-channel attack on RSA secret keys dubbed "Sliding right into disaster". For details see <https://eprint.iacr.org/2017/627>. [CVE-2017-7526] Checksums-Sha1: d2ec367313f777771a63bb25fc70a8e5eeee9314 2587 libgcrypt20_1.6.3-2+deb8u4.dsc a0a7eff13a3ef220f9a58bcacaa0b744b1883657 35372 libgcrypt20_1.6.3-2+deb8u4.debian.tar.xz e18411e897a5452e90d6c380df2fd2ebb79aee0e 65306 libgcrypt11-dev_1.5.4-3+really1.6.3-2+deb8u4_all.deb 1105b2a66bc630df4d8259069e2687a22caa99d4 679856 libgcrypt20-doc_1.6.3-2+deb8u4_all.deb Checksums-Sha256: 5e7816a66d609cd07c15c3e2e55c4c09b11592260a463f36d9bd4f5bc90ce02f 2587 libgcrypt20_1.6.3-2+deb8u4.dsc 36d11626006bcc4376659575780c2a28ff3a2fdca70b01944d4179716c9838f6 35372 libgcrypt20_1.6.3-2+deb8u4.debian.tar.xz f9bbf02640e32eb0805a4210f61256f9e2cdca0eac6877520d2abfcedea722ec 65306 libgcrypt11-dev_1.5.4-3+really1.6.3-2+deb8u4_all.deb 542ba4651150bc153439076ddb76c2f15189dac6e4cc8a4b991e781ced0ca201 679856 libgcrypt20-doc_1.6.3-2+deb8u4_all.deb Files: 2e8a227cab70f473d61e722ac190940d 2587 libs optional libgcrypt20_1.6.3-2+deb8u4.dsc f1124f4b4be7a1cf460e5d3afed9933d 35372 libs optional libgcrypt20_1.6.3-2+deb8u4.debian.tar.xz 6a28879dd5d852b64d54f1c738fbc1d6 65306 oldlibs extra libgcrypt11-dev_1.5.4-3+really1.6.3-2+deb8u4_all.deb eca4c5d23c4944f56e3297d543651f19 679856 doc optional libgcrypt20-doc_1.6.3-2+deb8u4_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0uCSA5741Jbt9PpepU8BhUOCFIQFAllXfQQACgkQpU8BhUOC FISJvQ/8DtOPmcYpT5YYm1vHKoYL3DCCkpFz4Uc/OUd5JhR4YCLXunBlrp7OUtxS DpFk4JFgxo+hu9BMF4BsAJizObBgTlabX5NheSyvxpPGFXzkPMOhERil0ghOBHdD Gixan/HHnCGhDx7UIIXzkqh/SE2FuYtcEUo4t79hKqZPdl/4LDbsWJZpJA9BRK3r aRcq5ie7ki0Oc+4S/27zt/Zk6zFDMXwiwjiFgG0aL5AjMJkxwubsm8BXQn76yI4W JyLljktYEwX2iVYM5vWRGXdfn6SIIACBnpcXiCImSaAjhAQZlBj1GTgSRPxrJoZy ZRQeWG2jbg4JeV+qGPO2D3B5wxBzH3sGR9sls9nKSMBSU9Q5ITxAvZuw8DWAxZXA Tko7jIbeRmhIKg/YJR8a+MbqL9av0a+uLosIINFhSE1t0SPcq6XsDmMAloiMKFOI bm4VLU63uLw2HxE3GnyNCKX1SoDCYfEkGq7uoqccJ4GHSg5qSX6plPvTVi3v/Klk Q7p70Hir0qmDvS44y1wTcKq1XWBl7LEvTBWVr9XtYaoAdUCDPxicO0zamYRTYx36 CG1+aJmEvF4uY+6XN5o4c2yRcncMdFw3LPhaSDKEH4imSXSJaTJJLlUfVr53qz2K fJXVtdgCvAUN89wxClCA3Y46+MX7dM3JGVYKrGr6hVQ/yf8KCig= =o/yo -----END PGP SIGNATURE-----