golang-go.crypto 1:0.0~git20200221.2aa609c-1 source package in Ubuntu


golang-go.crypto (1:0.0~git20200221.2aa609c-1) unstable; urgency=high

  * New upstream version 0.0~git20200221.2aa609c
    - ssh: return an error for malformed ed25519 public keys
      rather than panic (v0.0.0-20200220183623-bac4c82f6975).
      Fixes CVE-2020-9283 (Closes: #952462)
  * Previously uploaded upstream version 0.0~git20190701.4def268 contains:
    - salsa20/salsa: fix keystream loop in amd64 assembly when overflowing
      32-bit counter (commit b7391e9, 2019-03-20).  Fixes CVE-2019-11840
    - openpgp/clearsign: reject potentially misleading headers and messages
      (commit c05e17b, 2019-04-24).  Fixes CVE-2019-11841
  * debian/gbp.conf: Set debian-branch to debian/sid for DEP-14 conformance
  * Bump Standards-Version to 4.5.0 (no change)
  * debian/copyright: Add Upstream-Contact
  * Remove d/patches/0001-ssh-test-delete-TestInvalidTerminalMode.patch
    which has been applied upstream as commit 9756ffd
  * Build-Depends on dh-golang (>= 1.48~) to prevent
    "no non-test Go files" error in internal/wycheproof during build
  * Add d/patches/0001-skip-wycheproof_test.patch to skip test
    that access the Internet with "go mod download -json"
  * Override dh_auto_install with --no-binaries
    to prevent /usr/bin/acmeprobe from being built

 -- Anthony Fok <email address hidden>  Wed, 26 Feb 2020 13:36:38 -0700

Upload details

Uploaded by:
Debian Go Packaging Team on 2020-02-27
Uploaded to:
Original maintainer:
Debian Go Packaging Team
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section
Focal release on 2020-04-14 universe misc


Focal: [FULLYBUILT] amd64


File Size SHA-256 Checksum
golang-go.crypto_0.0~git20200221.2aa609c-1.dsc 2.4 KiB b130a6e2d104aad65e736bb41c01aa6fc4c1e16a139c31fc12c3d21df573912b
golang-go.crypto_0.0~git20200221.2aa609c.orig.tar.xz 1.5 MiB dcd8132ab5acd92dfe2fc8ce8e3c76f3a91f6c60bdfdac1df407b365c1ccd490
golang-go.crypto_0.0~git20200221.2aa609c-1.debian.tar.xz 5.6 KiB 1c9c458572ef8ee734672463159c344c1c4517587427726a968546dd1fed73f8

No changes file available.

Binary packages built by this source

golang-golang-x-crypto-dev: Supplementary Go cryptography libraries

 This package contains cryptographic algorithms and protocols not packaged in
 the main Go distribution, such as:
  - blowfish
  - nacl
  - openpgp
  - otr
  - sha3
  - ssh
 and many others.