-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 20 Jan 2024 07:56:15 +0100 Source: gnutls28 Binary: gnutls-bin gnutls-bin-dbgsym guile-gnutls guile-gnutls-dbgsym libgnutls-dane0 libgnutls-dane0-dbgsym libgnutls-openssl27 libgnutls-openssl27-dbgsym libgnutls28-dev libgnutls30 libgnutls30-dbgsym libgnutlsxx28 libgnutlsxx28-dbgsym Architecture: s390x Version: 3.7.1-5+deb11u5 Distribution: bullseye Urgency: medium Maintainer: s390x Build Daemon (zandonai) Changed-By: Andreas Metzler Description: gnutls-bin - GNU TLS library - commandline utilities guile-gnutls - GNU TLS library - GNU Guile bindings libgnutls-dane0 - GNU TLS library - DANE security support libgnutls-openssl27 - GNU TLS library - OpenSSL wrapper libgnutls28-dev - GNU TLS library - development files libgnutls30 - GNU TLS library - main runtime library libgnutlsxx28 - GNU TLS library - C++ runtime library Closes: 1061045 1061046 Changes: gnutls28 (3.7.1-5+deb11u5) bullseye; urgency=medium . * Cherrypick two CVE fixes from 3.8.3: Fix assertion failure when verifying a certificate chain with a cycle of cross signatures. CVE-2024-0567 GNUTLS-SA-2024-01-09 Closes: #1061045 Fix more timing side-channel inside RSA-PSK key exchange. CVE-2024-0553 GNUTLS-SA-2024-01-14 Closes: #1061046 Checksums-Sha1: 3b4af8a801317f59f39b3e865ec0d699f6a09256 902156 gnutls-bin-dbgsym_3.7.1-5+deb11u5_s390x.deb 83e28e870bbeae4cf0d1667130cd9605828e199e 629040 gnutls-bin_3.7.1-5+deb11u5_s390x.deb 92df2d41f4040983c9614b1ae92143b1ef5da88b 10980 gnutls28_3.7.1-5+deb11u5_s390x-buildd.buildinfo 14178191cf207a4274dae16bf9cc688cb963d4cb 239364 guile-gnutls-dbgsym_3.7.1-5+deb11u5_s390x.deb 76a1c2c35bd5344c5ff2ed24f436773ee3caa30f 443824 guile-gnutls_3.7.1-5+deb11u5_s390x.deb db80f15bc2fc30aaf3a821e53262935d1a0a1643 66332 libgnutls-dane0-dbgsym_3.7.1-5+deb11u5_s390x.deb dc0541fe673846a03c1695dea015fe8e5d89a2e4 393904 libgnutls-dane0_3.7.1-5+deb11u5_s390x.deb 3251fe0820fabbbb4d88e655921d6dfde53a7900 67060 libgnutls-openssl27-dbgsym_3.7.1-5+deb11u5_s390x.deb 17c929a762a9d83786631c247d6f8a51cdaada2a 393860 libgnutls-openssl27_3.7.1-5+deb11u5_s390x.deb 6599e56827aaeafb97e5d8ed28a23eefedd7794f 1188960 libgnutls28-dev_3.7.1-5+deb11u5_s390x.deb 7c61ff931ef69fa46ad8f1570cbdc1e45e8f4cbb 1876468 libgnutls30-dbgsym_3.7.1-5+deb11u5_s390x.deb cb775f0e041949bc48538f4bd84e8ab089f4927f 1228236 libgnutls30_3.7.1-5+deb11u5_s390x.deb 6c97b5b52d4607d261044bb1cba1a9170c14fd71 50576 libgnutlsxx28-dbgsym_3.7.1-5+deb11u5_s390x.deb bfcca9df87f9a9b29b46ee8da1c11a489107519f 13896 libgnutlsxx28_3.7.1-5+deb11u5_s390x.deb Checksums-Sha256: 1cfba954214eda2585c95ec280ff1c187cc47d7f871bfffbf18679f5e1fa7bb5 902156 gnutls-bin-dbgsym_3.7.1-5+deb11u5_s390x.deb 9740dca5340e89210701fc0372a4273641ddbba7c406b31a0aaeaf3b981ab3fa 629040 gnutls-bin_3.7.1-5+deb11u5_s390x.deb 283af48acf53d7e85939e6c2f6a456244bd626a8d3d3a33f064b593aecbadc8c 10980 gnutls28_3.7.1-5+deb11u5_s390x-buildd.buildinfo 7ecb166a17427ef58e23a7ed7c57da91da04714b8dee161e4ad42db70b2c9e36 239364 guile-gnutls-dbgsym_3.7.1-5+deb11u5_s390x.deb 2b00a4d8206e275e370d03a335307d1406760b3f4dbcc0bba8506771002ecbca 443824 guile-gnutls_3.7.1-5+deb11u5_s390x.deb ad6a2cf8b2631ac2a3b384b472c9ec1deccee3107abed245d5e57c4b279268e1 66332 libgnutls-dane0-dbgsym_3.7.1-5+deb11u5_s390x.deb dc396e87170c1ccbb1ce8c1008dd9dffe5bb2f2e976adad086c466255378036d 393904 libgnutls-dane0_3.7.1-5+deb11u5_s390x.deb 5bbffa26d86e350e80467f705a53c6c4318d0fd2df38809c874c9e36092b1588 67060 libgnutls-openssl27-dbgsym_3.7.1-5+deb11u5_s390x.deb edd178bc151e0a67e16274d1b3863201d27305a780a0d4bfe2b95628dc908043 393860 libgnutls-openssl27_3.7.1-5+deb11u5_s390x.deb 0939886fab8cb2df4ad55ba52352b207f2ae874e3f8ba2e5c09a2081cb2c5fa4 1188960 libgnutls28-dev_3.7.1-5+deb11u5_s390x.deb c6cce3fbad223eb82303c881553ff3b06d407c67b8a1e14c57a434e00a4e1b4a 1876468 libgnutls30-dbgsym_3.7.1-5+deb11u5_s390x.deb ca07c2b2362ff8909afc5d02df773f9e6341e294b356d457fce3ad451d9d31a6 1228236 libgnutls30_3.7.1-5+deb11u5_s390x.deb ef61612d2905592423adbe4f5f4726ff8b302d885093ce1ae876753e49873512 50576 libgnutlsxx28-dbgsym_3.7.1-5+deb11u5_s390x.deb 6f2d03876275ffdc6ec1a84d4313193ead099db307716d2c86c75903f90ecf7c 13896 libgnutlsxx28_3.7.1-5+deb11u5_s390x.deb Files: 3afc2b5bcb8557f8d3b5ce0e5c9e9b57 902156 debug optional gnutls-bin-dbgsym_3.7.1-5+deb11u5_s390x.deb b83ebea2f7e9d958cb31d3145223a63e 629040 net optional gnutls-bin_3.7.1-5+deb11u5_s390x.deb e9cc4702915fdb73833d1a20b927f681 10980 libs optional gnutls28_3.7.1-5+deb11u5_s390x-buildd.buildinfo 235ed64f1b35eab383f1a05e89d33fbc 239364 debug optional guile-gnutls-dbgsym_3.7.1-5+deb11u5_s390x.deb bd2e2edc37f94474a5dcd328103f776d 443824 lisp optional guile-gnutls_3.7.1-5+deb11u5_s390x.deb d222d6e08108afe0ba7a2868c552fc4a 66332 debug optional libgnutls-dane0-dbgsym_3.7.1-5+deb11u5_s390x.deb 3de23d6f3952f37b48746b2ea917f6c8 393904 libs optional libgnutls-dane0_3.7.1-5+deb11u5_s390x.deb ed192ebeb6ac2d806468f741ad074eac 67060 debug optional libgnutls-openssl27-dbgsym_3.7.1-5+deb11u5_s390x.deb 3a3bc2cc1a75f5254bd483ce843c5a86 393860 libs optional libgnutls-openssl27_3.7.1-5+deb11u5_s390x.deb 8452ef63dee0437bfc8db501d83893f7 1188960 libdevel optional libgnutls28-dev_3.7.1-5+deb11u5_s390x.deb 217909ffaaf9a7a266eaae2a79f57c96 1876468 debug optional libgnutls30-dbgsym_3.7.1-5+deb11u5_s390x.deb 2103cbc188e54f296f9f0a5575e69a84 1228236 libs optional libgnutls30_3.7.1-5+deb11u5_s390x.deb da9612d8bf464159e378cb7d0c5a3872 50576 debug optional libgnutlsxx28-dbgsym_3.7.1-5+deb11u5_s390x.deb d5601ecd2362e5aef821c3a2b8f7280e 13896 libs optional libgnutlsxx28_3.7.1-5+deb11u5_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEctqRAwcjFMIrbct74euoNlQ3ywQFAmYMdD8ACgkQ4euoNlQ3 ywT0FQ/+OOKERmqYtSDH+UpQI3+RnsqPlnW2lZoBoTLM8UMlLbUQF5JD8GohEp5Z ec96QeVehkBxyNT62OM+mtJP4TNvENoFrPH5HBDFcYs2ySn/Yas25ZuSNiLLUdVC wMuEpG4xtNtebdH45qU3vZHxH+gqQIcLdcVE+aja614D6JaP5TZQL031q9Gt5LER Xnokt/GQxmcJFg3ZzT1AmUKpRIyLvCI65RWwM4lgbVZODZ/2XNKHZeQuIO2saZs2 S9YjmzOPhiB2qTHkKdg4thcJ8JjMVTX7MobZdHXlb1vY7OHaBVO4grVH6p1M90hw vHMtEh+WN9aLVXDpkK3x5JeReUdfdS6nOaac+1PP/AERZnWklh5311s18eC2fsi8 Io8uXePb8IeqG0/ROUVQXolQHIOxLE+c6ZY7iVw3TgsEw5gfehbTAGHiPtkoWe+/ 2NnwpqODnX3bquEK5/ZfpfV7lMDh58Zd2Z35dKH2um0TTUUJ/Xp6tZcJsy5x43x3 ZrAVo6cbhoIViT8b9y8ecApsS8eBJflmYiRvnpb4LMfjTr2VF2AoBZT1krM7biSe 1NN7gKp8p210I86nkbkfVohspMnl8IwQx5nqcz6L5Yttgcnteo5dNPcHyNzeWt3U P7f86mnkm5m9xvSsTb78A6wOXAxjMr+GGmEt25khnGX5kWJVZEo= =YtBH -----END PGP SIGNATURE-----