-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 24 Jul 2017 18:42:23 +0200 Source: libtasn1-3 Binary: libtasn1-3-dev libtasn1-3-dbg libtasn1-3 libtasn1-3-bin Architecture: source amd64 Version: 2.13-2+deb7u5 Distribution: wheezy-security Urgency: high Maintainer: Debian GnuTLS Maintainers <pkg-gnutls-maint@lists.alioth.debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Description: libtasn1-3 - Manage ASN.1 structures (runtime) libtasn1-3-bin - Manage ASN.1 structures (binaries) libtasn1-3-dbg - Manage ASN.1 structures (debugging symbols) libtasn1-3-dev - Manage ASN.1 structures (development) Changes: libtasn1-3 (2.13-2+deb7u5) wheezy-security; urgency=high . * Non-maintainer upload by the Wheezy LTS Team. * CVE-2017-10790 The _asn1_check_identifier function in GNU Libtasn1 through 4.12 causes a NULL pointer dereference and crash when reading crafted input that triggers assignment of a NULL value within an asn1_node structure. It may lead to a remote denial of service attack. Checksums-Sha1: ab173fdb22ebee3c57f0a54e92c2c76e27bad43e 2492 libtasn1-3_2.13-2+deb7u5.dsc 89120584bfedd244dab92df99e955a174c481851 1964659 libtasn1-3_2.13.orig.tar.gz e1fb994b1260d1a827434100449a54848f5ac483 14449 libtasn1-3_2.13-2+deb7u5.debian.tar.gz 5b695ca72f449499470595e4d195c0c80d9b566f 390174 libtasn1-3-dev_2.13-2+deb7u5_amd64.deb 06488525354e759ab8fddc565901e8778936680e 153556 libtasn1-3-dbg_2.13-2+deb7u5_amd64.deb 85ecb0bbfae8140983bb8a697bb852a4cca96179 68880 libtasn1-3_2.13-2+deb7u5_amd64.deb 0008e62cd9bd9442142721555ea319e51ed317e0 53888 libtasn1-3-bin_2.13-2+deb7u5_amd64.deb Checksums-Sha256: 818f02ba2b4bd3278c2819df1918af3a274ef50dc76f9f4e19f5c04aebb74da8 2492 libtasn1-3_2.13-2+deb7u5.dsc a56e46483d1d42fe44ba58c9758620844042468d7c2d75f6318cdf3222745a91 1964659 libtasn1-3_2.13.orig.tar.gz a73cfde650ddc086a7681cae367d082b48a9454e225753cb0893180091d2c70c 14449 libtasn1-3_2.13-2+deb7u5.debian.tar.gz 2d83202b34c5a994c126f61a1deebfd0dd456b9b105c574d9d05320f9db89826 390174 libtasn1-3-dev_2.13-2+deb7u5_amd64.deb 21323c6b254673b64677faafd10169efc1380bc0ec14bdbd54965ea3c9c9ca75 153556 libtasn1-3-dbg_2.13-2+deb7u5_amd64.deb 5d0d8df202ef28bfadb16153c40640d65c88361172a0ca51fc233011615dbd55 68880 libtasn1-3_2.13-2+deb7u5_amd64.deb 216a690d9db17b23c75c23a00c369b1e81433fc0746da68eda12781e84c7d88e 53888 libtasn1-3-bin_2.13-2+deb7u5_amd64.deb Files: 1d3ad92fb9b98b14dc5f54352dbe67ed 2492 libs standard libtasn1-3_2.13-2+deb7u5.dsc df27eaddcc46172377e6b907e33ddc83 1964659 libs standard libtasn1-3_2.13.orig.tar.gz 3d5ade9c12b66502d64371559262a18e 14449 libs standard libtasn1-3_2.13-2+deb7u5.debian.tar.gz 64c4ecd7ac17bc88669642a774eb9444 390174 libdevel optional libtasn1-3-dev_2.13-2+deb7u5_amd64.deb a9a08271f6e13c00b92fe9414859e18a 153556 debug extra libtasn1-3-dbg_2.13-2+deb7u5_amd64.deb 69b79d700bb6bc9066b5ddfd4228728e 68880 libs standard libtasn1-3_2.13-2+deb7u5_amd64.deb be480fdb01fce146e9c1a3e4db4b3e02 53888 devel extra libtasn1-3-bin_2.13-2+deb7u5_amd64.deb -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAll2Lc9fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYRzOeD/sGFF3zfCDnAKccZ1RIAC0pFn34rm0y ETfLYEAm5aZgT4bWdH1Ub2OAuK8/o5xuLNVCD6zPGNJE7ThwSth2nhYYl566mh7g StGvGP0DedfTRoPx0vjMXAwl95xVhHMvR08PP1rdcScRoUzwScZi7PDa/GSCc9G7 tD8CXHjIJfGs9TvcLqt5GEF9k5PFoqckHUErl0hrTlYUgIoTPORbTSFrNMqbzVTi 54QD42Iix2Uvv6wEsVB6OjTuMQVKOHEOeG6/2qRWXCuDA8142Jyp35b8yr9HOcpb u0gfPpwLqd0KN8kZNmGrcVeDEMRJs8qOrOAruApIcqn1Ip9T2U0dm5sy5cmx87ni nJ8vqotGfH8vuaZG4CttRBpqkN+O9cg23YJ1UOrORU26BllLv24tFX82m26xXP1b qkGEPhlofdFQq0UY0e4QTrwv6ihOuz13VC5EQI46yhx9itcg7lbsVTdQQJNkPUy5 dG+UStew+rmrTsutIgbOAKLctniG9V6Zs+SIDNVgOtzvRr1Acxxxg1d6D5QMYiPY AkZ/wEhyQ6zfMQFedaknl++/WefOaK43YLZnsfz65wVM/ofj4bo5e+s6MC3v0Vlf C0kA1Vta3rHsrFfa4Xg+i3A2usz8k67z+OEACxHkRIoGCYrGHkeA5aX6HP5Dq/QE MFL+wWhz9qvLiw== =MfBy -----END PGP SIGNATURE-----