Format: 1.8 Date: Tue, 28 May 2019 13:18:12 -0400 Source: gnutls28 Binary: libgnutls28-dev libgnutls30 gnutls-bin gnutls-doc libgnutlsxx28 libgnutls-openssl27 libgnutls-dane0 Architecture: arm64 arm64_translations Version: 3.5.18-1ubuntu1.1 Distribution: bionic Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: gnutls-bin - GNU TLS library - commandline utilities gnutls-doc - GNU TLS library - documentation and examples libgnutls-dane0 - GNU TLS library - DANE security support libgnutls-openssl27 - GNU TLS library - OpenSSL wrapper libgnutls28-dev - GNU TLS library - development files libgnutls30 - GNU TLS library - main runtime library libgnutlsxx28 - GNU TLS library - C++ runtime library Changes: gnutls28 (3.5.18-1ubuntu1.1) bionic-security; urgency=medium . * SECURITY UPDATE: Lucky-13 issues - debian/patches/CVE-2018-1084x-1.patch: correctly account the length field in SHA384 HMAC in lib/algorithms/mac.c, lib/cipher.c. - debian/patches/CVE-2018-1084x-2.patch: always hash the same amount of blocks that would have been on minimum pad in lib/cipher.c. - debian/patches/CVE-2018-1084x-3.patch: require minimum padding under SSL3.0 in lib/cipher.c. - debian/patches/CVE-2018-1084x-4.patch: hmac-sha384 and sha256 ciphersuites were removed from defaults in lib/priority.c, tests/dtls1-2-mtu-check.c, tests/priorities.c. - debian/patches/CVE-2018-1084x-5.patch: fix test for SHA512 in tests/pkcs12_encode.c. - CVE-2018-10844 - CVE-2018-10845 - CVE-2018-10846 * SECURITY UPDATE: double free in cert verification API - debian/patches/CVE-2019-3829-1.patch: automatically NULLify after gnutls_free() in lib/includes/gnutls/gnutls.h.in. - debian/patches/CVE-2019-3829-2.patch: fix some casts in lib/extensions.c. - debian/patches/CVE-2019-3829-3.patch: fix dereference of NULL pointer in lib/x509/x509.c. - CVE-2019-3829 Checksums-Sha1: bac4efbf45401336ef1ece52dd912139950b5ed2 832056 gnutls-bin-dbgsym_3.5.18-1ubuntu1.1_arm64.ddeb 322294d90c8d632e935105a1be7482e5a496f5b5 220756 gnutls-bin_3.5.18-1ubuntu1.1_arm64.deb d9c2e1ec792cf7ecc9b4bd665f8afcd881d86068 9664 gnutls28_3.5.18-1ubuntu1.1_arm64.buildinfo f7500a70eac071211545159eb060ff51460bc1c1 252622 gnutls28_3.5.18-1ubuntu1.1_arm64_translations.tar.gz 8bf08b250997a1a4d1eaa6377f5e087732aa6f3a 46908 libgnutls-dane0-dbgsym_3.5.18-1ubuntu1.1_arm64.ddeb 5c76a9f440d26e54f9fbd06b0578aee6f6bc7a4d 19320 libgnutls-dane0_3.5.18-1ubuntu1.1_arm64.deb 059ea22181e0ad081556d52dba8f458cdee0d627 52844 libgnutls-openssl27-dbgsym_3.5.18-1ubuntu1.1_arm64.ddeb bbd9e619ab8aa8bd492f6c5c173e051c57b61e36 19040 libgnutls-openssl27_3.5.18-1ubuntu1.1_arm64.deb e831914b24f870412f79a5ef229ffb4269bdd9fe 639048 libgnutls28-dev_3.5.18-1ubuntu1.1_arm64.deb 3a4f5044f4328323649e041f2b27d3da5ee323da 2642368 libgnutls30-dbgsym_3.5.18-1ubuntu1.1_arm64.ddeb 31cdf7ad6780f019d33d73a60f11322827af981f 540248 libgnutls30_3.5.18-1ubuntu1.1_arm64.deb fb2f6f063a1d47238ce4e066f4064816a028f6a2 45900 libgnutlsxx28-dbgsym_3.5.18-1ubuntu1.1_arm64.ddeb ab268257e7ca19d97316d0d80cbdec514749e2d9 12940 libgnutlsxx28_3.5.18-1ubuntu1.1_arm64.deb Checksums-Sha256: 46aeb9dd7397a69bf22569befcb4b4ec178261efc179d3bff5290019fbaa49b0 832056 gnutls-bin-dbgsym_3.5.18-1ubuntu1.1_arm64.ddeb 2059b38ce130d935f4e2bd1333fe7ae9caa53351a3a7c556b7000b4f4c801e25 220756 gnutls-bin_3.5.18-1ubuntu1.1_arm64.deb 2b1880d657db624f5c7d63be1e2a5863df3b1e7e5390a2bc8cb301259dcd46d0 9664 gnutls28_3.5.18-1ubuntu1.1_arm64.buildinfo 49d79a7b2334a87093926b2a22abcca9f694f26e4e30a11234cb752a074189da 252622 gnutls28_3.5.18-1ubuntu1.1_arm64_translations.tar.gz b5821214858eabad0400b870e4275a5fb27eb56629c29ada615883a8a0192552 46908 libgnutls-dane0-dbgsym_3.5.18-1ubuntu1.1_arm64.ddeb 21188852b78a648bf3447a288903739e8495c9d0fa5d536df92b78d99525d10e 19320 libgnutls-dane0_3.5.18-1ubuntu1.1_arm64.deb 0073a34215cbfe47cb5ed82a950dea184bdcbbd319537a06c373ab3aa3ef84f4 52844 libgnutls-openssl27-dbgsym_3.5.18-1ubuntu1.1_arm64.ddeb ee665715a25faa107db1a8b050df1abad678bf7cc5f6a8f7a4659a3dd9343949 19040 libgnutls-openssl27_3.5.18-1ubuntu1.1_arm64.deb 03e9dee159fdd4d7de0db9f73f131ab0a9ccf8df0239d4e396ad3118d8cb0e1f 639048 libgnutls28-dev_3.5.18-1ubuntu1.1_arm64.deb fc9b1bfa79e4e0c634af538e12f34523950e0933099b0be491927d919d3747f8 2642368 libgnutls30-dbgsym_3.5.18-1ubuntu1.1_arm64.ddeb 060a0852250a95edfd8498bf143cc03e5446af285de8c8bd7441f50c83aea856 540248 libgnutls30_3.5.18-1ubuntu1.1_arm64.deb 1e62374397af7dbac764887f9a3d5a62c2a001c411aa5bad766fe029d4129908 45900 libgnutlsxx28-dbgsym_3.5.18-1ubuntu1.1_arm64.ddeb df397da0ffde5cd8d6d6f3bc95c3ce8a655cd1b0f9784738633c837ceaf2ccf0 12940 libgnutlsxx28_3.5.18-1ubuntu1.1_arm64.deb Files: 1a99cf98bb9f8909bd61956404797ea1 832056 debug optional gnutls-bin-dbgsym_3.5.18-1ubuntu1.1_arm64.ddeb 9da030e3b1616736b20df89ae2238000 220756 net optional gnutls-bin_3.5.18-1ubuntu1.1_arm64.deb 956e681db11f52de74f469e97f67a414 9664 libs optional gnutls28_3.5.18-1ubuntu1.1_arm64.buildinfo 4fc2d0590fb0caa568a96e2350952eab 252622 raw-translations - gnutls28_3.5.18-1ubuntu1.1_arm64_translations.tar.gz 3eef01ce5e3cc853d9e225f3445466bd 46908 debug optional libgnutls-dane0-dbgsym_3.5.18-1ubuntu1.1_arm64.ddeb 58e4027f8c987d7a70dda000dc2bdfe2 19320 libs optional libgnutls-dane0_3.5.18-1ubuntu1.1_arm64.deb b514ccf1f616f22b83fa0dd94bb3c795 52844 debug optional libgnutls-openssl27-dbgsym_3.5.18-1ubuntu1.1_arm64.ddeb 03413b6258ea270d2767d683d4be1616 19040 libs standard libgnutls-openssl27_3.5.18-1ubuntu1.1_arm64.deb 9fdadeaf15680aee62b22fbfdb7c7ae3 639048 libdevel optional libgnutls28-dev_3.5.18-1ubuntu1.1_arm64.deb 8f9f2fce3636564a0598d966270b5fec 2642368 debug optional libgnutls30-dbgsym_3.5.18-1ubuntu1.1_arm64.ddeb bc98660d39c4d819efc9949d9f1baa27 540248 libs standard libgnutls30_3.5.18-1ubuntu1.1_arm64.deb 27c210d89ef15e5b4f964cac2ec23944 45900 debug optional libgnutlsxx28-dbgsym_3.5.18-1ubuntu1.1_arm64.ddeb 0a2c51482c874c9780be3db14aac5f2b 12940 libs optional libgnutlsxx28_3.5.18-1ubuntu1.1_arm64.deb Original-Maintainer: Debian GnuTLS Maintainers