Format: 1.8 Date: Thu, 18 Apr 2024 09:54:34 -0400 Source: gnutls28 Binary: gnutls-bin libgnutls-dane0t64 libgnutls-openssl27t64 libgnutls28-dev libgnutls30t64 Built-For-Profiles: noudeb Architecture: riscv64 riscv64_translations Version: 3.8.3-1.1ubuntu3.1 Distribution: noble Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: gnutls-bin - GNU TLS library - commandline utilities libgnutls-dane0t64 - GNU TLS library - DANE security support libgnutls-openssl27t64 - GNU TLS library - OpenSSL wrapper libgnutls28-dev - GNU TLS library - development files libgnutls30t64 - GNU TLS library - main runtime library Changes: gnutls28 (3.8.3-1.1ubuntu3.1) noble-security; urgency=medium . * SECURITY UPDATE: side-channel leak via Minerva attack - debian/patches/CVE-2024-28834.patch: avoid normalization of mpz_t in deterministic ECDSA in lib/nettle/int/dsa-compute-k.c, lib/nettle/int/dsa-compute-k.h, lib/nettle/int/ecdsa-compute-k.c, lib/nettle/int/ecdsa-compute-k.h, lib/nettle/pk.c, tests/sign-verify-deterministic.c. - CVE-2024-28834 * SECURITY UPDATE: crash via specially-crafted cert bundle - debian/patches/CVE-2024-28835.patch: remove length limit of input in lib/gnutls_int.h, lib/x509/common.c, lib/x509/verify-high.c, tests/test-chains.h. - CVE-2024-28835 Checksums-Sha1: fdb4c0bef18c10be0e1d0c7c9490a6af24b09ab8 948604 gnutls-bin-dbgsym_3.8.3-1.1ubuntu3.1_riscv64.ddeb 07e684f778c74755a7a38e9ff3f62c942922e8ef 302634 gnutls-bin_3.8.3-1.1ubuntu3.1_riscv64.deb 0d4c6825ec7be3507d75a6d3cb8827ad3b0b5ddb 10328 gnutls28_3.8.3-1.1ubuntu3.1_riscv64.buildinfo ea1a50d06a6ce8b2091957e5be89d021487c4acf 427394 gnutls28_3.8.3-1.1ubuntu3.1_riscv64_translations.tar.gz 9400ad3384bc93d56e2dc75cb3c6eccda922f195 85292 libgnutls-dane0t64-dbgsym_3.8.3-1.1ubuntu3.1_riscv64.ddeb 2ec996a0e8de87d0174e2a616dd56b4d67d20d60 39886 libgnutls-dane0t64_3.8.3-1.1ubuntu3.1_riscv64.deb 4de64df7ee1c8683b6d72712ab4c51fe9dfda644 86188 libgnutls-openssl27t64-dbgsym_3.8.3-1.1ubuntu3.1_riscv64.ddeb d7f479b2b7bf1ee2f113dec439b0c19b332ce14f 39858 libgnutls-openssl27t64_3.8.3-1.1ubuntu3.1_riscv64.deb bf239d221b7aa6086e704a382301656683fb9f83 2618606 libgnutls28-dev_3.8.3-1.1ubuntu3.1_riscv64.deb b00c9ee63fcfc868349147c28870d6948b856558 1905762 libgnutls30t64-dbgsym_3.8.3-1.1ubuntu3.1_riscv64.ddeb 3109bafd709465b19cd5679bf7ae3dfda280cb51 1012266 libgnutls30t64_3.8.3-1.1ubuntu3.1_riscv64.deb Checksums-Sha256: c804eef330bdea44b9b580acf26a3854f28ddc64732942b4aedd13b0c0fa05ec 948604 gnutls-bin-dbgsym_3.8.3-1.1ubuntu3.1_riscv64.ddeb d8707f1e43f81fcf836cd842e1fe4bc11e8b8e98a7d7a571c48c6705444c770c 302634 gnutls-bin_3.8.3-1.1ubuntu3.1_riscv64.deb d75c0e7ac8bdfdaf4c7bf375c8d7ea5fac1b6d7406c2ec6e7035f461e266c87f 10328 gnutls28_3.8.3-1.1ubuntu3.1_riscv64.buildinfo 92e65b8e0e7e5850f19ce9c90b7ed7368e9293f2e03bf8fe36d739833b966c61 427394 gnutls28_3.8.3-1.1ubuntu3.1_riscv64_translations.tar.gz 03e97724b1487d45339aa2fc17aa3a166c6f09b3d99a636c50336e44e55dcbbd 85292 libgnutls-dane0t64-dbgsym_3.8.3-1.1ubuntu3.1_riscv64.ddeb 97047c60f4a89b4563e88d0a8fadb61fc4190a42c8dda58ecf5b96ae661d7d69 39886 libgnutls-dane0t64_3.8.3-1.1ubuntu3.1_riscv64.deb 8a9b2715b3a3ccc63c3c4074cbc37c44e3a2b37b492fddc8a78005fbd4455f84 86188 libgnutls-openssl27t64-dbgsym_3.8.3-1.1ubuntu3.1_riscv64.ddeb 327a8e2c003f3bcf4551e927fa675901aac79aae9b26c59a250848945c780f4d 39858 libgnutls-openssl27t64_3.8.3-1.1ubuntu3.1_riscv64.deb 53562b94f85f8ce92df92d816506ae4a40c2507d2ff224090b634ef54ebb83be 2618606 libgnutls28-dev_3.8.3-1.1ubuntu3.1_riscv64.deb 5c03130c9b8b79fd83c869eb94bf9ca085f2502e318fad17c48ba65d32e5db74 1905762 libgnutls30t64-dbgsym_3.8.3-1.1ubuntu3.1_riscv64.ddeb 0ac3fe64299a165f1dc9f90e19f25f9493b79f499fd755a01765fad1f9deb4a9 1012266 libgnutls30t64_3.8.3-1.1ubuntu3.1_riscv64.deb Files: cbc6e970fd1b667e6535034a8adff9e2 948604 debug optional gnutls-bin-dbgsym_3.8.3-1.1ubuntu3.1_riscv64.ddeb b6e4e1f8f30e64a4dd0a38c2880a9132 302634 net optional gnutls-bin_3.8.3-1.1ubuntu3.1_riscv64.deb e631b5bef8b99cb289fd524ee9e67e96 10328 libs optional gnutls28_3.8.3-1.1ubuntu3.1_riscv64.buildinfo af95fb8ddf5551c17ca80e6047072136 427394 raw-translations - gnutls28_3.8.3-1.1ubuntu3.1_riscv64_translations.tar.gz e448bedc1578383ad8c0ce74d3f7ea6a 85292 debug optional libgnutls-dane0t64-dbgsym_3.8.3-1.1ubuntu3.1_riscv64.ddeb b7a776f139534ede5e97fbe901be76b6 39886 libs optional libgnutls-dane0t64_3.8.3-1.1ubuntu3.1_riscv64.deb d552a41699a5a17efe74da28059041ce 86188 debug optional libgnutls-openssl27t64-dbgsym_3.8.3-1.1ubuntu3.1_riscv64.ddeb 8744f02728a9c03fa25bdbbd1697a3fb 39858 libs optional libgnutls-openssl27t64_3.8.3-1.1ubuntu3.1_riscv64.deb 6c3da0d8b2b441cebe4553ea45788e06 2618606 libdevel optional libgnutls28-dev_3.8.3-1.1ubuntu3.1_riscv64.deb 1d90e021366da46388e7ec5a2b7fc895 1905762 debug optional libgnutls30t64-dbgsym_3.8.3-1.1ubuntu3.1_riscv64.ddeb 0cc5a4f90e6f28de63e40bbf6d335b06 1012266 libs optional libgnutls30t64_3.8.3-1.1ubuntu3.1_riscv64.deb Original-Maintainer: Debian GnuTLS Maintainers