Change log for nettle package in Ubuntu

140 of 40 results
Published in eoan-release on 2019-04-18
Published in disco-release on 2019-01-29
Deleted in disco-proposed (Reason: moved to release)
nettle (3.4.1-1) unstable; urgency=low

  * Final upstream release (identical to RC1).

 -- Magnus Holmgren <email address hidden>  Sat, 26 Jan 2019 13:19:09 +0100

Available diffs

Superseded in disco-release on 2019-01-29
Deleted in disco-proposed on 2019-01-30 (Reason: moved to release)
nettle (3.4.1~rc1-1) unstable; urgency=low

  * New upstream release (Closes: #915276).

 -- Magnus Holmgren <email address hidden>  Tue, 04 Dec 2018 21:04:39 +0100

Available diffs

Superseded in disco-release on 2018-12-05
Published in cosmic-release on 2018-05-01
Published in bionic-release on 2018-02-08
Deleted in bionic-proposed (Reason: moved to release)
nettle (3.4-1) unstable; urgency=low

  * New upstream release (Closes: #884013).
    * multiarch_dev.patch: no longer replace definition of GMP_NUMB_BITS;
      upstream changed it to "n/a" when mini-gmp isn't used.
  * debian/rules: Switch to dh_update_autotools_config.
  * Rename libnettle5.docs -> libnettle6.docs so that the NEWS and README
    files will be included again.
  * Bump Standards-Version to 4.1.2.

 -- Magnus Holmgren <email address hidden>  Tue, 12 Dec 2017 19:27:18 +0100

Available diffs

Superseded in bionic-release on 2018-02-08
Published in artful-release on 2017-10-10
Deleted in artful-proposed (Reason: moved to release)
nettle (3.3-2) unstable; urgency=low

  * multiarch_dev.patch: Replace definition of GMP_NUMB_BITS calculated by
    configure with the same calculation to be done at compile time (only
    used if this package would be rebuilt with --enable-mini-gmp).  Thus
    declare nettle-dev Multi-Arch: same (Closes: #856160).
  * Upgrade to Debhelper compat level 9.
  * Drop old style -dbg package and switch to automatically created
    -dbgsym packages. Since the old package was built with Debhelper level
    8 there are actually no file conflicts.
  * Declare nettle-bin Multi-Arch: foreign.
  * Bump Standards-Version to 4.1.0.

 -- Magnus Holmgren <email address hidden>  Sun, 10 Sep 2017 23:25:31 +0200

Available diffs

Published in precise-updates on 2017-02-06
Published in precise-security on 2017-02-06
nettle (2.4-1ubuntu0.1) precise-security; urgency=medium

  * SECURITY UPDATE: RSA cache timing side-channel attack
    - debian/patches/CVE-2016-6489.patch: use mpz_powm_sec and check for
      invalid keys in dsa-sign.c, rsa-decrypt.c, rsa-md5-sign.c,
      rsa-sha1-sign.c, rsa-sha256-sign.c, rsa-sha512-sign.c, rsa-sign.c,
      rsa.c, testsuite/rsa-test.c.
    - CVE-2016-6489

 -- Marc Deslauriers <email address hidden>  Fri, 03 Feb 2017 08:55:02 -0500
Published in xenial-updates on 2017-02-06
Published in xenial-security on 2017-02-06
nettle (3.2-1ubuntu0.16.04.1) xenial-security; urgency=medium

  * SECURITY UPDATE: RSA cache timing side-channel attack
    - debian/patches/CVE-2016-6489.patch: use mpz_powm_sec and check for
      invalid keys in bignum.h, configure.ac, dsa-sign.c, rsa-blind.c,
      rsa-sign-tr.c, rsa-sign.c, rsa.c, testsuite/rsa-test.c.
    - CVE-2016-6489

 -- Marc Deslauriers <email address hidden>  Fri, 03 Feb 2017 08:22:52 -0500
Published in trusty-updates on 2017-02-06
Published in trusty-security on 2017-02-06
nettle (2.7.1-1ubuntu0.2) trusty-security; urgency=medium

  * SECURITY UPDATE: RSA cache timing side-channel attack
    - debian/patches/CVE-2016-6489.patch: use mpz_powm_sec and check for
      invalid keys in dsa-sign.c, rsa-blind.c, rsa-pkcs1-sign-tr.c,
      rsa-pkcs1-sign.c, rsa-sign.c, rsa.c, testsuite/rsa-test.c,
      rsa-decrypt-tr.c, rsa-decrypt.c.
    - CVE-2016-6489

 -- Marc Deslauriers <email address hidden>  Fri, 03 Feb 2017 08:40:39 -0500
Obsolete in yakkety-updates on 2018-01-23
Obsolete in yakkety-security on 2018-01-23
nettle (3.2-1ubuntu0.16.10.1) yakkety-security; urgency=medium

  * SECURITY UPDATE: RSA cache timing side-channel attack
    - debian/patches/CVE-2016-6489.patch: use mpz_powm_sec and check for
      invalid keys in bignum.h, configure.ac, dsa-sign.c, rsa-blind.c,
      rsa-sign-tr.c, rsa-sign.c, rsa.c, testsuite/rsa-test.c.
    - CVE-2016-6489

 -- Marc Deslauriers <email address hidden>  Fri, 03 Feb 2017 08:16:22 -0500
Superseded in artful-release on 2017-10-10
Obsolete in zesty-release on 2018-06-22
Deleted in zesty-proposed on 2018-06-22 (Reason: moved to release)
nettle (3.3-1) unstable; urgency=low

  * New upstream release.
    * Includes fix for CVE-2016-6489 - "RSA code is vulnerable to cache
      sharing related attacks" (Closes: #832983).
  * Include --raw option in nettle-hash(1) manpage (Closes: #808648).
  * Bump Standards-Version to 3.9.8.

 -- Magnus Holmgren <email address hidden>  Sun, 02 Oct 2016 18:44:03 +0200

Available diffs

Obsolete in wily-updates on 2018-01-22
Obsolete in wily-security on 2018-01-22
nettle (3.1.1-4ubuntu0.1) wily-security; urgency=medium

  * SECURITY UPDATE: miscomputation bugs in secp-256r1 modulo functions
    - debian/patches/CVE-2015-8803_8805.patch: fix carry propagation bugs
      in ecc-256.c.
    - CVE-2015-8803
    - CVE-2015-8805
  * SECURITY UPDATE: carry folding bug in x86_64 ecc_384_modp
    - debian/patches/CVE-2015-8804.patch: fix carry propagation bug in
      x86_64/ecc-384-modp.asm.
    - CVE-2015-8804

 -- Marc Deslauriers <email address hidden>  Wed, 10 Feb 2016 13:20:47 -0500
Superseded in trusty-updates on 2017-02-06
Superseded in trusty-security on 2017-02-06
nettle (2.7.1-1ubuntu0.1) trusty-security; urgency=medium

  * SECURITY UPDATE: miscomputation bugs in secp-256r1 modulo functions
    - debian/patches/CVE-2015-8803_8805.patch: fix carry propagation bugs
      in ecc-256.c.
    - CVE-2015-8803
    - CVE-2015-8805
  * SECURITY UPDATE: carry folding bug in x86_64 ecc_384_modp
    - debian/patches/CVE-2015-8804.patch: fix carry propagation bug in
      x86_64/ecc-384-modp.asm.
    - CVE-2015-8804

 -- Marc Deslauriers <email address hidden>  Wed, 10 Feb 2016 13:34:57 -0500
Superseded in zesty-release on 2016-11-03
Obsolete in yakkety-release on 2018-01-23
Published in xenial-release on 2016-02-07
Deleted in xenial-proposed (Reason: moved to release)
nettle (3.2-1) unstable; urgency=medium

  * New upstream release.
    * Includes fixes for CVE-2015-8803, CVE-2015-8804, and CVE-2015-8805
      (Closes: #813679).

 -- Magnus Holmgren <email address hidden>  Sat, 06 Feb 2016 18:59:30 +0100
Superseded in xenial-release on 2016-02-07
Obsolete in wily-release on 2018-01-22
Deleted in wily-proposed on 2018-01-22 (Reason: moved to release)
nettle (3.1.1-4) unstable; urgency=low

  * multiarch_dev.patch (new): Remove compiler version info causing
    nettle-dev for different architectures to be incompatible with each
    other from nettle-stdint.h (Closes: #783699).
  * Rearrange debian/copyright to comply with the machine-readable format
    specification.

 -- Magnus Holmgren <email address hidden>  Mon, 03 Aug 2015 20:02:18 +0200

Available diffs

Superseded in wily-release on 2015-08-04
Deleted in wily-proposed on 2015-08-05 (Reason: moved to release)
nettle (3.1.1-3) unstable; urgency=low

  * Switch libgmp10-dev Build-Depends to libgmp-dev (Closes: #783085).

 -- Magnus Holmgren <email address hidden>  Mon, 01 Jun 2015 23:57:24 +0200

Available diffs

Superseded in wily-release on 2015-06-24
Obsolete in vivid-release on 2018-01-18
Deleted in vivid-proposed on 2018-01-19 (Reason: moved to release)
nettle (2.7.1-5) unstable; urgency=medium


  * Add code to transition /usr/share/doc/nettle-dbg from directory to
    symlink (Closes: #774919).
  * Also add missing Pre-Depends: multiarch-support to nettle-dbg.

 -- Magnus Holmgren <email address hidden>  Sun, 11 Jan 2015 20:27:20 +0100

Available diffs

Superseded in vivid-release on 2015-01-12
Deleted in vivid-proposed on 2015-01-13 (Reason: moved to release)
nettle (2.7.1-4) unstable; urgency=medium


  * Use dh_installdocs --link-doc to create symlinks and add correct
    dependencies (Closes: #773022).
  * Bump Standards-Version to 3.9.6.
  * Add upstream PGP signing key.
  * Add GNU server URLs to watch file.

 -- Magnus Holmgren <email address hidden>  Sun, 21 Dec 2014 01:14:02 +0100
Superseded in vivid-release on 2014-12-21
Deleted in vivid-proposed on 2014-12-22 (Reason: moved to release)
nettle (2.7.1-3build1) vivid; urgency=medium

  * No change rebuild to get debug symbols on all architectures.
 -- Brian Murray <email address hidden>   Thu, 13 Nov 2014 11:35:52 -0800
Superseded in vivid-release on 2014-11-13
Obsolete in utopic-release on 2016-11-03
Deleted in utopic-proposed on 2016-11-03 (Reason: moved to release)
nettle (2.7.1-3) unstable; urgency=low


  * Use -fPIC instead of -fpic by default (Closes: #755769); needed on
    sparc64 and shouldn't be noticeable elsewhere.

 -- Magnus Holmgren <email address hidden>  Tue, 29 Jul 2014 17:20:39 +0200

Available diffs

Superseded in utopic-release on 2014-07-31
Deleted in utopic-proposed on 2014-08-02 (Reason: moved to release)
nettle (2.7.1-2) unstable; urgency=low


  * libhogweed2.symbols: Tag some internal functions implementing
    operations not available in GMP before version 6.0 as optional
    (Closes: #743087).
  * Bump Standards-Version to 3.9.5.

 -- Magnus Holmgren <email address hidden>  Fri, 18 Apr 2014 21:02:56 +0200

Available diffs

Superseded in utopic-release on 2014-04-26
Published in trusty-release on 2013-10-18
Obsolete in saucy-release on 2015-04-24
Deleted in saucy-proposed (Reason: moved to release)
nettle (2.7.1-1) unstable; urgency=low


  * New upstream bugfix release.

 -- Magnus Holmgren <email address hidden>  Wed, 29 May 2013 19:25:35 +0200

Available diffs

Superseded in saucy-release on 2013-05-30
Deleted in saucy-proposed on 2013-05-31 (Reason: moved to release)
nettle (2.7-2) unstable; urgency=low


  * Tag some (ECC related) symbols that only exist on some architectures.

 -- Magnus Holmgren <email address hidden>  Tue, 07 May 2013 22:57:14 +0200

Available diffs

Superseded in saucy-proposed on 2013-05-09
nettle (2.7-1) unstable; urgency=low


  * New upstream release (Closes: #706081).
  * Include watch file improvements from Bart Martens <email address hidden>
    via the QA system.

 -- Magnus Holmgren <email address hidden>  Sat, 04 May 2013 19:50:28 +0200
Superseded in saucy-release on 2013-05-10
Obsolete in raring-release on 2015-04-24
Deleted in raring-proposed on 2015-04-27 (Reason: moved to release)
nettle (2.4-3) unstable; urgency=high


  * Add postinst script that replaces old documentation directory (from
    before 1.15-4) in nettle-bin with symlink (Closes: #692950).
  * Spell check package descriptions (Closes: #680627). Thanks to Filipus
    Klutiero.

 -- Magnus Holmgren <email address hidden>  Fri, 16 Nov 2012 21:13:25 +0100

Available diffs

Superseded in raring-release on 2012-11-17
Obsolete in quantal-release on 2015-04-24
nettle (2.4-2) unstable; urgency=low


  * Drop README.source; not needed since the package was converted to
    format 3.0.
  * Correct errors in DEP 5-format debian/copyright.
  * Use dpkg-buildflags to set CFLAGS et al.
  * Bump Standards-Version to 3.9.3.

 -- Magnus Holmgren <email address hidden>  Sat, 23 Jun 2012 14:41:45 +0200

Available diffs

Superseded in quantal-release on 2012-06-24
Published in precise-release on 2011-10-17
nettle (2.4-1) unstable; urgency=low

  * New upstream bugfix release.

Available diffs

Superseded in precise-release on 2011-10-17
Obsolete in oneiric-release on 2015-04-24
nettle (2.1-2) unstable; urgency=low

  * Upload to unstable.
  * Increase Debhelper compat level to 7.
  * debian/rules: Add build-indep and build-arch targets.
  * debian/copyright: Add entry for dsa2sexp.c.
  * No longer suggest lsh-utils-doc as an alternative to lsh-doc.

Available diffs

Superseded in oneiric-release on 2011-05-21
Obsolete in natty-release on 2013-06-04
nettle (2.0-2ubuntu1) natty; urgency=low

  * Configure with --disable-assembler for natty to fix a FTBFS. Should
    be revisited with 2.1 in the o-series.
 -- Matthias Klose <email address hidden>   Wed, 30 Mar 2011 18:08:59 +0200

Available diffs

Superseded in natty-release on 2011-03-31
Obsolete in maverick-release on 2013-03-05
Obsolete in lucid-release on 2016-10-26
nettle (2.0-2) unstable; urgency=low

  * rsa2sexp_algorithm_name.dpatch (new): Use a default algorithm name
    that LSH understands in the sexp representation of an RSA key, so that
    pkcs1-conv can be used to convert existing OpenSSH private keys.
  * debian/control: Add ${misc:Depends} to all packages lacking it.
  * debian/control: nettle-dev: Depend on dpkg (>= 1.15.4) | install-info
    as recommended for the transition to triggerized install-info.
  * Upgraded to Standards-Version 3.8.3 with the previous change.

Available diffs

Superseded in lucid-release on 2009-11-06
Obsolete in karmic-release on 2013-03-04
nettle (1.15-6) unstable; urgency=low

  * No longer install sexp-conv as an alternative; conflict with lsh-utils
    prior to 2.0.4-dfsg-1, which depends on nettle-bin instead of shipping
    a copy of sexp-conv (Closes: #510942). Drop nettle-bin.postinst and
    nettle-bin.prerm (nettle-bin.prerm will remove the alternative on
    upgrade, which is actually a bug, but works out fine in this case).
  * Switch to Debhelper level 5. Remove files that don't exist from install
    lists (copied from a template, apparently).
  * Upgrade to Standards-Version 3.8.1:
    + Add debian/README.source (ยง 4.9).
  * Add debian/libnettle2.symbols.

 -- Ubuntu Archive Auto-Sync <email address hidden>   Wed,  29 Apr 2009 12:05:28 +0100

Available diffs

Superseded in karmic-release on 2009-04-29
Obsolete in jaunty-release on 2013-02-28
Obsolete in intrepid-release on 2013-02-20
nettle (1.15-5) unstable; urgency=low

  * New maintainer email address.
  * Bring debian/control format up-to-date with Homepage and Vcs fields.
  * Add machine-readable copyright information to debian/copyright and
    clarify licensing of nettle-lfib-stream.1 and pkcs1-conv.1. The
    machine-readable information may not be completely accurate at this
    point due to the many different authors and licenses.
  * Don't ignore make potential distclean errors.
  * debian/libnettle-dev.doc-base: Change section to Programming/C
    following the abolishion of the Apps section.
  * Bump Standards-Version to 3.7.3 without any changes.

 -- Ubuntu Archive Auto-Sync <email address hidden>   Fri,  02 May 2008 02:20:37 +0100
Superseded in intrepid-release on 2008-05-03
Obsolete in hardy-release on 2015-04-24
Obsolete in gutsy-release on 2011-09-16
nettle (1.15-4) unstable; urgency=low

  * Add manpage for nettle-lfib-stream(1) (Closes: #413293).
  * Add manpage for pkcs1-conv(1) (Closes: #413294).
  * Correct manpage for sexp-conv(1).

 -- Ubuntu Archive Auto-Sync <email address hidden>   Tue,  12 Jun 2007 11:46:39 +0100
Superseded in gutsy-release on 2007-06-12
nettle (1.15-3) unstable; urgency=low

  * Use dh_install instead of dh_movefiles.
  * Run "make check" by default.
  * Ship nettle.pdf in libnettle-dev.
  * Include PDF and Info formats in doc-base control file.
  * Clean up the libnettle-dev examples directory. There should only be
    source files. Note that most of the examples aren't made to be
    compiled outside of the nettle source tree, except sha-example.c,
    which is the example found in the documentation.
  * Move descore.README and TODO from libnettle2.docs to
    libnettle-dev.docs, and also add README and NEWS to the latter.
  * Make debian/copyright more correct.
  * Add pkcs1-conv to nettle-bin package description.

 -- Ubuntu Archive Auto-Sync <email address hidden>   Mon,  11 Jun 2007 18:46:02 +0100
Superseded in gutsy-release on 2007-06-11
nettle (1.15-2) unstable; urgency=high

  * Fix serious regression: The -lgmp added in 1.8-1 fell off in 1.15-1
    (Closes: #415034).
  * Use dpatch to handle patches.
  * Make package binNMUable.
  * Add XS-Vcs-* fields to debian/control.
  * Make dependencies on libnettle2 versioned.

 -- Ubuntu Archive Auto-Sync <email address hidden>   Fri,  18 May 2007 09:37:20 +0100
Superseded in gutsy-release on 2007-05-18
nettle (1.15-1) unstable; urgency=low

  * New maintainer (Closes: #411677).
  * New upstream version. The non-free IETF RFC has been removed by
    upstream.
  * Updated Standards-Version to 3.7.2 without any changes.
  * Converted doc-base and copyright files to UTF-8.
  * Added extra cleanup to clean target of debian/rules so that
    dpkg-buildpackage can be run more than once.
  * debian/watch: updated.
  * debian/control: added autotools-dev as a build-dependency.
  * debian/rules: don't include config.guess and config.sub in
    .diff.gz.

 -- Ubuntu Archive Auto-Sync <email address hidden>   Fri,  27 Apr 2007 00:48:36 +0100
Superseded in gutsy-release on 2007-04-27
Obsolete in feisty-release on 2009-08-20
Superseded in feisty-release on 2007-01-29
nettle (1.14.1-1) unstable; urgency=low

  * Removed non-DFSG file from the archive and disabled the
    corresponding test case
  * Source package contains non-free IETF RFC/I-D's (Closes: #393400)
  * Since there is no upstream release available, a "fake" version number
    is added to the version.

 -- Ubuntu Archive Auto-Sync <email address hidden>   Tue,  07 Nov 2006 03:07:26 +0000
Superseded in feisty-release on 2006-11-08
Obsolete in edgy-release on 2008-06-19
nettle (1.14-1) unstable; urgency=low

  * The latest upstream version

 -- Ubuntu Archive Auto-Sync <email address hidden>   Thu,  15 Jun 2006 15:08:56 +0100
Superseded in edgy-release on 2006-06-15
Obsolete in dapper-release on 2011-09-06
Superseded in dapper-release on 2006-02-03
nettle (1.12-3) unstable; urgency=high


  * Force a recompile to match the new libgmp3 package name

 -- Marek Habersack <email address hidden>  Tue, 19 Jul 2005 12:01:28 +0200
Obsolete in breezy-release on 2008-03-25
nettle (1.12-2build1) breezy; urgency=low


  * Rebuild, change library package names.

 -- Matthias Klose <email address hidden>  Mon, 23 May 2005 23:06:28 +0000
Obsolete in hoary-release on 2008-03-19
nettle (1.12-1) unstable; urgency=high


  * The latest upstream release
  * sexp-conv is installed as sexp-conv.nettle and registered with the
    alternatives system now.
  * added the sexp-conv mainpage borrowed from the lsh-utils package.

 -- Marek Habersack <email address hidden>  Tue, 30 Nov 2004 01:45:49 +0100
Obsolete in warty-release on 2008-01-09
nettle (1.10-1) unstable; urgency=low


  * The latest upstream version

 -- Marek Habersack <email address hidden>  Tue,  4 May 2004 15:56:02 +0200
140 of 40 results