Format: 1.8 Date: Fri, 12 Apr 2024 09:12:36 -0400 Source: gnutls28 Binary: gnutls-bin libgnutls-dane0 libgnutls-openssl27 libgnutls28-dev libgnutls30 Built-For-Profiles: noudeb Architecture: ppc64el ppc64el_translations Version: 3.8.1-4ubuntu1.3 Distribution: mantic Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: gnutls-bin - GNU TLS library - commandline utilities libgnutls-dane0 - GNU TLS library - DANE security support libgnutls-openssl27 - GNU TLS library - OpenSSL wrapper libgnutls28-dev - GNU TLS library - development files libgnutls30 - GNU TLS library - main runtime library Changes: gnutls28 (3.8.1-4ubuntu1.3) mantic-security; urgency=medium . * SECURITY UPDATE: side-channel leak via Minerva attack - debian/patches/CVE-2024-28834.patch: avoid normalization of mpz_t in deterministic ECDSA in lib/nettle/int/dsa-compute-k.c, lib/nettle/int/dsa-compute-k.h, lib/nettle/int/ecdsa-compute-k.c, lib/nettle/int/ecdsa-compute-k.h, lib/nettle/pk.c, tests/sign-verify-deterministic.c. - CVE-2024-28834 * SECURITY UPDATE: crash via specially-crafted cert bundle - debian/patches/CVE-2024-28835.patch: remove length limit of input in lib/gnutls_int.h, lib/x509/common.c, lib/x509/verify-high.c, tests/test-chains.h. - CVE-2024-28835 Checksums-Sha1: b0f3a967360f6e26cc528137b07d35fc006bc5fb 658732 gnutls-bin-dbgsym_3.8.1-4ubuntu1.3_ppc64el.ddeb 60c2fb92d8209d89add7f648a4776f6fd036285c 287612 gnutls-bin_3.8.1-4ubuntu1.3_ppc64el.deb a95d924f77060edef097e81f1100e496d3d6eec4 9763 gnutls28_3.8.1-4ubuntu1.3_ppc64el.buildinfo 237c3b5267e39454d444db8d1886fae546ea92aa 427129 gnutls28_3.8.1-4ubuntu1.3_ppc64el_translations.tar.gz 111283aa4d4fd478db496d3627d91e5864dfdfb0 48718 libgnutls-dane0-dbgsym_3.8.1-4ubuntu1.3_ppc64el.ddeb 40c132e7d0ba0d0c35fd739e5d5ace6f3c2520b4 24034 libgnutls-dane0_3.8.1-4ubuntu1.3_ppc64el.deb f91362bfc9f397a1821a0843b448afaf60295a90 51188 libgnutls-openssl27-dbgsym_3.8.1-4ubuntu1.3_ppc64el.ddeb 40deaccc615bd2b0a90bf7bf81eef91ed8e0ae93 23498 libgnutls-openssl27_3.8.1-4ubuntu1.3_ppc64el.deb 40c570dc22ba285c92e894afa788907e93b5a192 1186520 libgnutls28-dev_3.8.1-4ubuntu1.3_ppc64el.deb 0ab72b35460951f14ee84120f47ef12f58a9c916 2616602 libgnutls30-dbgsym_3.8.1-4ubuntu1.3_ppc64el.ddeb 922051abada907b857ccd657fed14784bb47f7a7 1044648 libgnutls30_3.8.1-4ubuntu1.3_ppc64el.deb Checksums-Sha256: 4f3aa2dff9d6a3b5271fa0dfc64cd3f91ccfb35ee32b4644a7b7ffe524cbd12e 658732 gnutls-bin-dbgsym_3.8.1-4ubuntu1.3_ppc64el.ddeb 8f0ef2d8a074cc66e45e652a546d29bf2cf3acfaa3b8326f3d528e51590cb267 287612 gnutls-bin_3.8.1-4ubuntu1.3_ppc64el.deb 216e29520f5ccef94ceb6664d0a463895579820391c43c45ea852218e41124b1 9763 gnutls28_3.8.1-4ubuntu1.3_ppc64el.buildinfo 320943c7bd96b0056e002adebfe46b3ad75b6380d5973bfcc81e267dd487884b 427129 gnutls28_3.8.1-4ubuntu1.3_ppc64el_translations.tar.gz 869ee9bb98ab490cc0f7e7be126f744b22dd725fb1c7acc6da29a882b82386f4 48718 libgnutls-dane0-dbgsym_3.8.1-4ubuntu1.3_ppc64el.ddeb fbfac87c9ba58df794d15464b5ba2ebaa319e28af94091a96721ce4ccf09ba57 24034 libgnutls-dane0_3.8.1-4ubuntu1.3_ppc64el.deb 642fb13c944f918b8240108a941fa8eef5f806cd5fef7b9ffa8e7c9dfaaef78f 51188 libgnutls-openssl27-dbgsym_3.8.1-4ubuntu1.3_ppc64el.ddeb 1d165b75fbb2e0f9294089b06d567847d0d7d66a66ab4bcea3a956637c525523 23498 libgnutls-openssl27_3.8.1-4ubuntu1.3_ppc64el.deb 801ca375832593ac926a6953d3cc9463f14384edf5ef801fee2a807eea9a7dcc 1186520 libgnutls28-dev_3.8.1-4ubuntu1.3_ppc64el.deb fde775b0cf75869c8348fc0118fa834890d1b80c2172c61c025bd957a063475f 2616602 libgnutls30-dbgsym_3.8.1-4ubuntu1.3_ppc64el.ddeb 0a59946a911a758e6344fdd44b82d451a3b4dff8d2d80ea0a5b693fb75118153 1044648 libgnutls30_3.8.1-4ubuntu1.3_ppc64el.deb Files: 3654cc46928637d06930b60926fc32b4 658732 debug optional gnutls-bin-dbgsym_3.8.1-4ubuntu1.3_ppc64el.ddeb d09fc99ec9848ed73431c8ae505542ae 287612 net optional gnutls-bin_3.8.1-4ubuntu1.3_ppc64el.deb ab859d7860145a53a9aa111600f70429 9763 libs optional gnutls28_3.8.1-4ubuntu1.3_ppc64el.buildinfo cfc6b799b2c8f6cc5887812c8176a169 427129 raw-translations - gnutls28_3.8.1-4ubuntu1.3_ppc64el_translations.tar.gz 2cd2495921a757afeab13a4ed524ac38 48718 debug optional libgnutls-dane0-dbgsym_3.8.1-4ubuntu1.3_ppc64el.ddeb 47b32e63e0f7711f03151a1d333de8ba 24034 libs optional libgnutls-dane0_3.8.1-4ubuntu1.3_ppc64el.deb 3c2f70cbf20572c75b5b61947c69d633 51188 debug optional libgnutls-openssl27-dbgsym_3.8.1-4ubuntu1.3_ppc64el.ddeb 10e0044ad6840c496f2f3bf8619e59e0 23498 libs optional libgnutls-openssl27_3.8.1-4ubuntu1.3_ppc64el.deb b28789f6b5357badcaeae794894161d1 1186520 libdevel optional libgnutls28-dev_3.8.1-4ubuntu1.3_ppc64el.deb 2c2ec9116adbc4ebacf1e1d31001b3eb 2616602 debug optional libgnutls30-dbgsym_3.8.1-4ubuntu1.3_ppc64el.ddeb b7f6a750aaf90619bf9b06cd2af1ade6 1044648 libs optional libgnutls30_3.8.1-4ubuntu1.3_ppc64el.deb Original-Maintainer: Debian GnuTLS Maintainers