Format: 1.8 Date: Tue, 08 Oct 2019 22:53:23 +0200 Source: openssl Architecture: source Version: 1.1.1d-1+ubuntu16.04.1+deb.sury.org+2 Distribution: xenial Urgency: high Maintainer: Debian OpenSSL Team Changed-By: Ondřej Surý Closes: 759811 767207 773601 794326 802591 813191 816239 823774 827028 839575 843064 844234 844715 848957 852017 852900 852920 859191 860254 861145 863367 863707 864080 867240 869856 875423 878303 882007 888305 891570 891797 892276 894282 895844 907631 910459 911389 912067 913558 923516 926315 Changes: openssl (1.1.1d-1+ubuntu16.04.1+deb.sury.org+2) xenial; urgency=medium . * No-change backport to xenial . openssl (1.1.1d-1) unstable; urgency=medium . * New upstream version - CVE-2019-1549 (Fixed a fork protection issue). - CVE-2019-1547 (Compute ECC cofactors if not provided during EC_GROUP construction). - CVE-2019-1563 (Fixed a padding oracle in PKCS7_dataDecode and CMS_decrypt_set1_pkey). * Update symbol list . openssl (1.1.1c-1) unstable; urgency=medium . * New upstream version - CVE-2019-1543 (Prevent over long nonces in ChaCha20-Poly1305) * Update symbol list . openssl (1.1.1b-2) unstable; urgency=medium . * Fix BUF_MEM regression (Closes: #923516) * Fix error when config can't be opened (Closes: #926315) * Ship an openssl.cnf in libssl1.1-udeb.dirs . openssl (1.1.1b-1) unstable; urgency=medium . [ Sebastian Andrzej Siewior ] * Add Breaks on lighttpd (Closes: #913558). . [ Kurt Roeckx ] * New upstream version * Update symbol list . openssl (1.1.1a-1) unstable; urgency=medium . * Add Breaks on python-boto (See: #909545) * New upstream version - CVE-2018-0734 (Timing vulnerability in DSA signature generation) - CVE-2018-0735 (Timing vulnerability in ECDSA signature generation) - Update symbol file for 1.1.1a . openssl (1.1.1-2) unstable; urgency=medium . [ Sebastian Andrzej Siewior ] * Add Breaks on isync (See: #906955) * Fix autopkgtest (Closes: #910459) . [ Kurt Roeckx ] * Add Breaks on python-imaplib2 (See: #907079) * Add news entry regarding default TLS version and security level (Closes: #875423, #907631, #911389, #912067). . openssl (1.1.1-1) unstable; urgency=medium . * New upstream version. - Update symbol file for 1.1.1 - CVE-2018-0732 (actually since pre8). * Add Breaks on python-httplib2 (See: #907278) * Add hardening=+all. * Update to policy 4.2.1 - Less verbose testsuite with terse - Use RRR=no . openssl (1.1.1~~pre9-1) unstable; urgency=medium . * New upstream version. - Support the final TLS 1.3 version (RFC 8446) * Upload to unstable . openssl (1.1.1~~pre8-1) experimental; urgency=medium . * New upstream version. . openssl (1.1.1~~pre7-1) experimental; urgency=medium . * Drop afalgeng on kfreebsd-* which go enabled because they inherit from the linux target. * Fix debian-rules-sets-dpkg-architecture-variable. * Update to policy 4.1.4 - only Suggest: libssl-doc instead Recommends (only documentation and example code is shipped). - drop Priority: important. - use signing-key.asc and a https links for downloads * Use compat 11. - this moves the examples to /usr/share/doc/libssl-{doc->dev}/demos but it seems to make sense. * Add a 25-test_verify.t for autopkgtest which runs against intalled openssl binary. * Fix CVE-2018-0737 (Closes: #895844). . openssl (1.1.1~~pre6-2) experimental; urgency=medium . * Update libssl1.1.symbols . openssl (1.1.1~~pre6-1) experimental; urgency=medium . * New upstream version * Increase default security level from 1 to 2. This moves from the 80 bit security level to the 112 bit securit level and will require 2048 bit RSA and DHE keys. . openssl (1.1.1~~pre4-1) experimental; urgency=medium . * Update to 1.1.1-pre4 (Closes: #892276, #894282). * Add riscv64 target (Closes: #891797). . openssl (1.1.1~~pre3-1) experimental; urgency=medium . * Update to 1.1.1-pre3 * Don't suggest 1024 bit RSA key to be typical (Closes: #878303). * Don't insist on TLS1.3 cipher for * Add a udeb for libssl, based on similar changes done in Ubuntu starting in version 0.9.8o-4ubuntu1 (Closes: #802591) Patch from Margarita Manterola * Add support for nios2 (Closes: #816239) Based on patch from Marek Vasut * Update Spanish translation from Manuel "Venturi" Porras Peralta (Closes: #773601) * Don't build an i586 optimized version anymore, the default already targets that. Patch from Sven Joachim (Closes: #759811) Checksums-Sha1: 3921f59ff17cbc67104e04577cfe4ccd08d2604b 2612 openssl_1.1.1d-1+ubuntu16.04.1+deb.sury.org+2.dsc 7e6aecd3f150d608b72c765aa3f8c0eb975c1648 9012933 openssl_1.1.1d.orig.tar.gz a64d419a7509e6b458739be3c3f3cd16ae3f8067 84164 openssl_1.1.1d-1+ubuntu16.04.1+deb.sury.org+2.debian.tar.xz 86b2aec2858bf5e9e1a56a94b08939930e3261b2 7480 openssl_1.1.1d-1+ubuntu16.04.1+deb.sury.org+2_source.buildinfo Checksums-Sha256: f33b3d5dce8571eb9eb4579940295531e1b94abbc61a644ec2cb311e5fc55dc7 2612 openssl_1.1.1d-1+ubuntu16.04.1+deb.sury.org+2.dsc db227f74232c57e8c7d6490e89f9e81dee543b4959c19676348062ce2f81cbe4 9012933 openssl_1.1.1d.orig.tar.gz fd5376d85fc40683fe5927b2c9812a4d27a9cdc66f2d121ba7f69151d154285e 84164 openssl_1.1.1d-1+ubuntu16.04.1+deb.sury.org+2.debian.tar.xz 8d34710cd679a80e6da300fded7ed4fa21e2a97bf997e671052f09cdab5b98db 7480 openssl_1.1.1d-1+ubuntu16.04.1+deb.sury.org+2_source.buildinfo Files: 67db29671273b8e26dc5e557210927f0 2612 utils optional openssl_1.1.1d-1+ubuntu16.04.1+deb.sury.org+2.dsc 905985dcf3a16e63c777b69cf868898f 9012933 utils optional openssl_1.1.1d.orig.tar.gz a6d57f78c1981af491ddf7437c4e2462 84164 utils optional openssl_1.1.1d-1+ubuntu16.04.1+deb.sury.org+2.debian.tar.xz a719e4fd099ba8c07bb93140012fe1ab 7480 utils optional openssl_1.1.1d-1+ubuntu16.04.1+deb.sury.org+2_source.buildinfo