Format: 1.8 Date: Thu, 18 Apr 2024 09:54:34 -0400 Source: gnutls28 Binary: gnutls-bin libgnutls-dane0t64 libgnutls-openssl27t64 libgnutls28-dev libgnutls30t64 Built-For-Profiles: noudeb Architecture: ppc64el ppc64el_translations Version: 3.8.3-1.1ubuntu3.1 Distribution: noble Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: gnutls-bin - GNU TLS library - commandline utilities libgnutls-dane0t64 - GNU TLS library - DANE security support libgnutls-openssl27t64 - GNU TLS library - OpenSSL wrapper libgnutls28-dev - GNU TLS library - development files libgnutls30t64 - GNU TLS library - main runtime library Changes: gnutls28 (3.8.3-1.1ubuntu3.1) noble-security; urgency=medium . * SECURITY UPDATE: side-channel leak via Minerva attack - debian/patches/CVE-2024-28834.patch: avoid normalization of mpz_t in deterministic ECDSA in lib/nettle/int/dsa-compute-k.c, lib/nettle/int/dsa-compute-k.h, lib/nettle/int/ecdsa-compute-k.c, lib/nettle/int/ecdsa-compute-k.h, lib/nettle/pk.c, tests/sign-verify-deterministic.c. - CVE-2024-28834 * SECURITY UPDATE: crash via specially-crafted cert bundle - debian/patches/CVE-2024-28835.patch: remove length limit of input in lib/gnutls_int.h, lib/x509/common.c, lib/x509/verify-high.c, tests/test-chains.h. - CVE-2024-28835 Checksums-Sha1: d7312c9359dfa8c7c73c474df800899bd064d18a 661670 gnutls-bin-dbgsym_3.8.3-1.1ubuntu3.1_ppc64el.ddeb 912465946d3a9342c3804de55909b638f6d2ea42 290388 gnutls-bin_3.8.3-1.1ubuntu3.1_ppc64el.deb e82978910c7365c956023a50c9fd3de2384eeced 10506 gnutls28_3.8.3-1.1ubuntu3.1_ppc64el.buildinfo 6c8e0ed443175826d8c936f4de7fd07c93c2b4e3 428080 gnutls28_3.8.3-1.1ubuntu3.1_ppc64el_translations.tar.gz 3d25ab54ea4a5a5568e99d2045bb770225878576 48736 libgnutls-dane0t64-dbgsym_3.8.3-1.1ubuntu3.1_ppc64el.ddeb 7ca7e60209d75f9878250ee4d512abc884dfa30f 24706 libgnutls-dane0t64_3.8.3-1.1ubuntu3.1_ppc64el.deb 28ccc2831fcf90bf2adbf0d6bff4859ffa2a00a0 51424 libgnutls-openssl27t64-dbgsym_3.8.3-1.1ubuntu3.1_ppc64el.ddeb 2dfdf27eb03b78d8142f439cd38ce8b4857f95e4 24174 libgnutls-openssl27t64_3.8.3-1.1ubuntu3.1_ppc64el.deb aa172ae3c93c2d682dfc06c4d1eb538027e7fc54 1202332 libgnutls28-dev_3.8.3-1.1ubuntu3.1_ppc64el.deb 04093cc9b98b0c898c40dfb12f34d49c72cafc26 2617626 libgnutls30t64-dbgsym_3.8.3-1.1ubuntu3.1_ppc64el.ddeb 7fe62144c60d84904d3b93cc1ddff41fa1c659db 1056716 libgnutls30t64_3.8.3-1.1ubuntu3.1_ppc64el.deb Checksums-Sha256: 9d1f8260cb5bbeef7f6139a3e654d18aa35c371d89a08206aa51eea86e70d22c 661670 gnutls-bin-dbgsym_3.8.3-1.1ubuntu3.1_ppc64el.ddeb e0e3a6e250978ce53426daa7be1cba46238b5ac2cd84da18278b1c91d7003c7a 290388 gnutls-bin_3.8.3-1.1ubuntu3.1_ppc64el.deb 51175c984aa9e1bc4d9e39ebefcffd156838bc9d4620524fef8c493c4c769bb9 10506 gnutls28_3.8.3-1.1ubuntu3.1_ppc64el.buildinfo 9582e1e4d135c20bf3642ee2c87686d94ff6e459a8f1a4c2bfb8e09faaaa1ed9 428080 gnutls28_3.8.3-1.1ubuntu3.1_ppc64el_translations.tar.gz 6ee2d685b4ca3807e0b164c9e5214062d3498e3ade96fe9ce2054cb036d9c753 48736 libgnutls-dane0t64-dbgsym_3.8.3-1.1ubuntu3.1_ppc64el.ddeb 019009035e8970de2a7707eba0f5b7f7f6a8c43dec69e4b5749ec47969f48483 24706 libgnutls-dane0t64_3.8.3-1.1ubuntu3.1_ppc64el.deb cdf240bd001402da9df74d747fd8294b24521dc5921704c15266675a8b815868 51424 libgnutls-openssl27t64-dbgsym_3.8.3-1.1ubuntu3.1_ppc64el.ddeb 48609009934e441e9adc476511328f6f206c2e560c0b48dc380ec135d906f5db 24174 libgnutls-openssl27t64_3.8.3-1.1ubuntu3.1_ppc64el.deb 767c1423db0408b47c7d90208d87b29bdae3e47b43a54e24a265c7b59414c8c7 1202332 libgnutls28-dev_3.8.3-1.1ubuntu3.1_ppc64el.deb 18eb99aee4751c192d30e093f7c1021c160a403916cbef54c880f0b4c3630ec5 2617626 libgnutls30t64-dbgsym_3.8.3-1.1ubuntu3.1_ppc64el.ddeb dd85ac5efa3a69358f6c023f5a0d27b3c98ed7a3305e9ca777b34be835632448 1056716 libgnutls30t64_3.8.3-1.1ubuntu3.1_ppc64el.deb Files: c6988dd764fb780a5e49c1cf8c0db19b 661670 debug optional gnutls-bin-dbgsym_3.8.3-1.1ubuntu3.1_ppc64el.ddeb 0c29aa4cdd159acd9ba6ddd06d6a8c08 290388 net optional gnutls-bin_3.8.3-1.1ubuntu3.1_ppc64el.deb e122388f50e59928275d384902b0f70c 10506 libs optional gnutls28_3.8.3-1.1ubuntu3.1_ppc64el.buildinfo ed31f1de7729dbb168fa5fdd0646c4f0 428080 raw-translations - gnutls28_3.8.3-1.1ubuntu3.1_ppc64el_translations.tar.gz 6f316fd016bb5d16ff8e42271c7487c1 48736 debug optional libgnutls-dane0t64-dbgsym_3.8.3-1.1ubuntu3.1_ppc64el.ddeb 14b33c36517d8a1f67202e70778efe1a 24706 libs optional libgnutls-dane0t64_3.8.3-1.1ubuntu3.1_ppc64el.deb 2670fc174d338bdcef5eee33834ca8a0 51424 debug optional libgnutls-openssl27t64-dbgsym_3.8.3-1.1ubuntu3.1_ppc64el.ddeb fb0c301d3e2ee0029e4df57cf3113156 24174 libs optional libgnutls-openssl27t64_3.8.3-1.1ubuntu3.1_ppc64el.deb cab623f49c219946652f8d8a900a5fba 1202332 libdevel optional libgnutls28-dev_3.8.3-1.1ubuntu3.1_ppc64el.deb d7d955e22ab23ea8f253f96fe92aafad 2617626 debug optional libgnutls30t64-dbgsym_3.8.3-1.1ubuntu3.1_ppc64el.ddeb bd60297b31f9fa203de9c6f43f83eb3d 1056716 libs optional libgnutls30t64_3.8.3-1.1ubuntu3.1_ppc64el.deb Original-Maintainer: Debian GnuTLS Maintainers