Format: 1.8 Date: Thu, 18 Apr 2024 09:54:34 -0400 Source: gnutls28 Binary: gnutls-bin libgnutls-dane0t64 libgnutls-openssl27t64 libgnutls28-dev libgnutls30t64 Built-For-Profiles: noudeb Architecture: arm64 arm64_translations Version: 3.8.3-1.1ubuntu3.1 Distribution: noble Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: gnutls-bin - GNU TLS library - commandline utilities libgnutls-dane0t64 - GNU TLS library - DANE security support libgnutls-openssl27t64 - GNU TLS library - OpenSSL wrapper libgnutls28-dev - GNU TLS library - development files libgnutls30t64 - GNU TLS library - main runtime library Changes: gnutls28 (3.8.3-1.1ubuntu3.1) noble-security; urgency=medium . * SECURITY UPDATE: side-channel leak via Minerva attack - debian/patches/CVE-2024-28834.patch: avoid normalization of mpz_t in deterministic ECDSA in lib/nettle/int/dsa-compute-k.c, lib/nettle/int/dsa-compute-k.h, lib/nettle/int/ecdsa-compute-k.c, lib/nettle/int/ecdsa-compute-k.h, lib/nettle/pk.c, tests/sign-verify-deterministic.c. - CVE-2024-28834 * SECURITY UPDATE: crash via specially-crafted cert bundle - debian/patches/CVE-2024-28835.patch: remove length limit of input in lib/gnutls_int.h, lib/x509/common.c, lib/x509/verify-high.c, tests/test-chains.h. - CVE-2024-28835 Checksums-Sha1: 8f3fc888217ad958703942d3af8609ae53882eff 702424 gnutls-bin-dbgsym_3.8.3-1.1ubuntu3.1_arm64.ddeb f8a4e48eab487d63fe07377e749f605e1bccee9d 266560 gnutls-bin_3.8.3-1.1ubuntu3.1_arm64.deb b0bfc999d1867843ed1089d55d8854179cd3dfef 10441 gnutls28_3.8.3-1.1ubuntu3.1_arm64.buildinfo 1c645d771207c410eb0b5822b253ac635a990ec7 428578 gnutls28_3.8.3-1.1ubuntu3.1_arm64_translations.tar.gz f4e603bc1df9616ae38cff13ab816179ac438f3a 47720 libgnutls-dane0t64-dbgsym_3.8.3-1.1ubuntu3.1_arm64.ddeb 764bfe305621b44653ec673c1201725ea7008839 23520 libgnutls-dane0t64_3.8.3-1.1ubuntu3.1_arm64.deb 853ffe0c0a6499ae5bef68b4060e6e6ea7e7f06b 50064 libgnutls-openssl27t64-dbgsym_3.8.3-1.1ubuntu3.1_arm64.ddeb d420e1898320deafb76da48316e0b35dc4d39bdc 23520 libgnutls-openssl27t64_3.8.3-1.1ubuntu3.1_arm64.deb 6bd87dbcdb8b6813ede01c79b46b97074e532f29 1114358 libgnutls28-dev_3.8.3-1.1ubuntu3.1_arm64.deb 4235b93065ce9f5a59b53501da0c7ff04925151b 2265308 libgnutls30t64-dbgsym_3.8.3-1.1ubuntu3.1_arm64.ddeb 31f46db6b0a7bb828ffd7c36421da3bd4dbb2e5a 935364 libgnutls30t64_3.8.3-1.1ubuntu3.1_arm64.deb Checksums-Sha256: 6108497f7e1957833a6ce279a8af0aab3cf97301f35b4410527e1f31d86ad368 702424 gnutls-bin-dbgsym_3.8.3-1.1ubuntu3.1_arm64.ddeb b5f8845dc274c58c3471e524007b81455dc082e2d005575626f68045bb2e6dd2 266560 gnutls-bin_3.8.3-1.1ubuntu3.1_arm64.deb 1442776ab2cf00f7aec700d708396220ea66972a520facfe46220fe0f9dd1d32 10441 gnutls28_3.8.3-1.1ubuntu3.1_arm64.buildinfo be3fb11953a426dc80082bb1136772b4d51f0ad51cfa60d5ac8917c0236acbc7 428578 gnutls28_3.8.3-1.1ubuntu3.1_arm64_translations.tar.gz 5a717d188b90c46516a9cf35c897dce72cbf2c322f876fd6fa920df220f93b39 47720 libgnutls-dane0t64-dbgsym_3.8.3-1.1ubuntu3.1_arm64.ddeb 59c8f486863bdb113d0b88fb5f79cf57b7ec2e16cd6d3deffe44408a01b686df 23520 libgnutls-dane0t64_3.8.3-1.1ubuntu3.1_arm64.deb f12c5ab304c1b3036049975576079e871a0e8d032b021032a1e8aa395e2cc23f 50064 libgnutls-openssl27t64-dbgsym_3.8.3-1.1ubuntu3.1_arm64.ddeb 7e88d22b8991e6e2693091e0a853e6347a42c562297914eff7e02941a05624b7 23520 libgnutls-openssl27t64_3.8.3-1.1ubuntu3.1_arm64.deb e9a45b2a6076e1c297e4a433aeca18a927e93311fa7aacd7c9811daecd3ceb29 1114358 libgnutls28-dev_3.8.3-1.1ubuntu3.1_arm64.deb 8e2ef63ea94415ec05eb9790d46c9a71e5fff816672b593bbb0091b4166a8057 2265308 libgnutls30t64-dbgsym_3.8.3-1.1ubuntu3.1_arm64.ddeb cb2e62c035a0bc13f559ebec3f482b72e8398514dc18becd3b08d10e3b594f2b 935364 libgnutls30t64_3.8.3-1.1ubuntu3.1_arm64.deb Files: 898fa81ee3950ee405c9f633efcdf591 702424 debug optional gnutls-bin-dbgsym_3.8.3-1.1ubuntu3.1_arm64.ddeb c7158237798a856e30639a8d8877bebf 266560 net optional gnutls-bin_3.8.3-1.1ubuntu3.1_arm64.deb 2b12bd78cc34d2f4b85f7f6752bc9550 10441 libs optional gnutls28_3.8.3-1.1ubuntu3.1_arm64.buildinfo f705ad253559591f248d211689288eaa 428578 raw-translations - gnutls28_3.8.3-1.1ubuntu3.1_arm64_translations.tar.gz 462847e2bf9c0bd6946ae66a6013a6bd 47720 debug optional libgnutls-dane0t64-dbgsym_3.8.3-1.1ubuntu3.1_arm64.ddeb 5ffa7857b54a87b9ef60dc7670358ebe 23520 libs optional libgnutls-dane0t64_3.8.3-1.1ubuntu3.1_arm64.deb 50a57c81c4a8f5b3d4aff2775f9a1fee 50064 debug optional libgnutls-openssl27t64-dbgsym_3.8.3-1.1ubuntu3.1_arm64.ddeb 6401808e9ab7c01ffa35209b3bd19007 23520 libs optional libgnutls-openssl27t64_3.8.3-1.1ubuntu3.1_arm64.deb 312df5c6f93426ea4b70cc0febfd6bab 1114358 libdevel optional libgnutls28-dev_3.8.3-1.1ubuntu3.1_arm64.deb abdd0077a33d82cdc8e3f8e35bb495c1 2265308 debug optional libgnutls30t64-dbgsym_3.8.3-1.1ubuntu3.1_arm64.ddeb deeaf8bdfbc1dbbe2ced2fb1366e69f2 935364 libs optional libgnutls30t64_3.8.3-1.1ubuntu3.1_arm64.deb Original-Maintainer: Debian GnuTLS Maintainers