Format: 1.8 Date: Tue, 28 May 2019 13:18:12 -0400 Source: gnutls28 Binary: libgnutls28-dev libgnutls30 gnutls-bin gnutls-doc libgnutlsxx28 libgnutls-openssl27 libgnutls-dane0 Architecture: armhf armhf_translations Version: 3.5.18-1ubuntu1.1 Distribution: bionic Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: gnutls-bin - GNU TLS library - commandline utilities gnutls-doc - GNU TLS library - documentation and examples libgnutls-dane0 - GNU TLS library - DANE security support libgnutls-openssl27 - GNU TLS library - OpenSSL wrapper libgnutls28-dev - GNU TLS library - development files libgnutls30 - GNU TLS library - main runtime library libgnutlsxx28 - GNU TLS library - C++ runtime library Changes: gnutls28 (3.5.18-1ubuntu1.1) bionic-security; urgency=medium . * SECURITY UPDATE: Lucky-13 issues - debian/patches/CVE-2018-1084x-1.patch: correctly account the length field in SHA384 HMAC in lib/algorithms/mac.c, lib/cipher.c. - debian/patches/CVE-2018-1084x-2.patch: always hash the same amount of blocks that would have been on minimum pad in lib/cipher.c. - debian/patches/CVE-2018-1084x-3.patch: require minimum padding under SSL3.0 in lib/cipher.c. - debian/patches/CVE-2018-1084x-4.patch: hmac-sha384 and sha256 ciphersuites were removed from defaults in lib/priority.c, tests/dtls1-2-mtu-check.c, tests/priorities.c. - debian/patches/CVE-2018-1084x-5.patch: fix test for SHA512 in tests/pkcs12_encode.c. - CVE-2018-10844 - CVE-2018-10845 - CVE-2018-10846 * SECURITY UPDATE: double free in cert verification API - debian/patches/CVE-2019-3829-1.patch: automatically NULLify after gnutls_free() in lib/includes/gnutls/gnutls.h.in. - debian/patches/CVE-2019-3829-2.patch: fix some casts in lib/extensions.c. - debian/patches/CVE-2019-3829-3.patch: fix dereference of NULL pointer in lib/x509/x509.c. - CVE-2019-3829 Checksums-Sha1: a37d0d9228fb8fa9b237e6a06a0304e6a4e79783 790996 gnutls-bin-dbgsym_3.5.18-1ubuntu1.1_armhf.ddeb 33d4eef3491716e037f72f56beaa2a2d32165906 220016 gnutls-bin_3.5.18-1ubuntu1.1_armhf.deb 4bb6f389ea8ed49c1364c0e34ae06c680fa1bce9 9596 gnutls28_3.5.18-1ubuntu1.1_armhf.buildinfo 68408be0e0e55bdc6c8eea02edbcae4832dbe350 252591 gnutls28_3.5.18-1ubuntu1.1_armhf_translations.tar.gz 1a746f2f189f306b5b6ce5604e73c5079757a61c 44604 libgnutls-dane0-dbgsym_3.5.18-1ubuntu1.1_armhf.ddeb c780e5e80bedee2fdf288a6ca8a3fc3661145003 18388 libgnutls-dane0_3.5.18-1ubuntu1.1_armhf.deb 6d41e755f30227f2d4815f6c90499a77b844a0ec 50868 libgnutls-openssl27-dbgsym_3.5.18-1ubuntu1.1_armhf.ddeb 76bc28f281699f4276da3b92e941094bc46acbf2 18400 libgnutls-openssl27_3.5.18-1ubuntu1.1_armhf.deb 08f2c757772e8d602dab239194af587adf7262f3 617468 libgnutls28-dev_3.5.18-1ubuntu1.1_armhf.deb 932c9d87232185200a2fd6542c8b8a4f656d1bda 2437428 libgnutls30-dbgsym_3.5.18-1ubuntu1.1_armhf.ddeb 25f6d3a35116f6098c16ef87ebe6c4cced04ddba 584848 libgnutls30_3.5.18-1ubuntu1.1_armhf.deb 57615f42e0b008aa9185c941b90c81a2f9b21e85 46156 libgnutlsxx28-dbgsym_3.5.18-1ubuntu1.1_armhf.ddeb f819b23408bfda38ec6f2271d2053ee4a8b05ba7 11956 libgnutlsxx28_3.5.18-1ubuntu1.1_armhf.deb Checksums-Sha256: a8f0bd7f77145f63bc594d0c91d7c5ba5c930479bfeac945dac294e5827bd24e 790996 gnutls-bin-dbgsym_3.5.18-1ubuntu1.1_armhf.ddeb 70dce28474f66f2d5ae0edfea26cb329545e4290e686ab9230bc9902905d5144 220016 gnutls-bin_3.5.18-1ubuntu1.1_armhf.deb ddabada0599a51b0d87cf46957e87926f23923e7dd456333480d482446941750 9596 gnutls28_3.5.18-1ubuntu1.1_armhf.buildinfo cdd9fff51c53ebdc467bbad67c5e1ea33f932daf7d588a413fd2f258dab08a18 252591 gnutls28_3.5.18-1ubuntu1.1_armhf_translations.tar.gz 42581b0d257ae8fdebe475a7d37c6f1a7af1443025fedfc0d7f0be1b5884d634 44604 libgnutls-dane0-dbgsym_3.5.18-1ubuntu1.1_armhf.ddeb 4e0ae1c2333724b960908f7c691081010789debd0492189b6190a372433d5d0f 18388 libgnutls-dane0_3.5.18-1ubuntu1.1_armhf.deb fd5a2bfc3565021f4de63c279d466c56197ae341462c21eb2d2801af402a93b1 50868 libgnutls-openssl27-dbgsym_3.5.18-1ubuntu1.1_armhf.ddeb d6e4a5c84bddd00fe5282128f8001019b2fc638d1045ad947d683af0034346b6 18400 libgnutls-openssl27_3.5.18-1ubuntu1.1_armhf.deb 9aeb47b628d5198e33492f518baeaff24c7f9df99fadf1c4a39236ffb3ca8339 617468 libgnutls28-dev_3.5.18-1ubuntu1.1_armhf.deb 944d3e932d031da73c19f6e28aaeb3c8d9a2e8768fab3d1410d66761455b8b46 2437428 libgnutls30-dbgsym_3.5.18-1ubuntu1.1_armhf.ddeb b6ee8bb18ce09a1147597a4c0c1c321e57d03305824b38ba9d9991b380911755 584848 libgnutls30_3.5.18-1ubuntu1.1_armhf.deb 516673e9660cec85db7d185581b2bb7c1c5ce6524eaafe51cb3bdb3a012f3732 46156 libgnutlsxx28-dbgsym_3.5.18-1ubuntu1.1_armhf.ddeb e649df21f68c3a996570b6d9892f01b70999f81f5fec38571164363ea951b62d 11956 libgnutlsxx28_3.5.18-1ubuntu1.1_armhf.deb Files: ed4c8e096908c52df078edc33efa1e74 790996 debug optional gnutls-bin-dbgsym_3.5.18-1ubuntu1.1_armhf.ddeb e6389cb1a71039bb7ede51569c575896 220016 net optional gnutls-bin_3.5.18-1ubuntu1.1_armhf.deb 5ada02f52bd3255cd3a8959a21afcf2d 9596 libs optional gnutls28_3.5.18-1ubuntu1.1_armhf.buildinfo 73b8504d532a47fcfaa010165077a64b 252591 raw-translations - gnutls28_3.5.18-1ubuntu1.1_armhf_translations.tar.gz 509949c548b2859c1272a577d8c6bfa0 44604 debug optional libgnutls-dane0-dbgsym_3.5.18-1ubuntu1.1_armhf.ddeb fe76f9cefad501dfc59c04e4e407d061 18388 libs optional libgnutls-dane0_3.5.18-1ubuntu1.1_armhf.deb 1c6b34df188fcca3a5a112d962f513f7 50868 debug optional libgnutls-openssl27-dbgsym_3.5.18-1ubuntu1.1_armhf.ddeb a1fe57802c01c90b9bc45b3f72951b45 18400 libs standard libgnutls-openssl27_3.5.18-1ubuntu1.1_armhf.deb 418fb9f08f1e734f848ee5b2939e9fa2 617468 libdevel optional libgnutls28-dev_3.5.18-1ubuntu1.1_armhf.deb 35f04150a6e894c1799bbb474530ad75 2437428 debug optional libgnutls30-dbgsym_3.5.18-1ubuntu1.1_armhf.ddeb 7b189db90c6854c6c6de0db31c28d73c 584848 libs standard libgnutls30_3.5.18-1ubuntu1.1_armhf.deb 271ae833663e57587be263251ea21126 46156 debug optional libgnutlsxx28-dbgsym_3.5.18-1ubuntu1.1_armhf.ddeb f312d73b7a41f38ef18237ea36da2db3 11956 libs optional libgnutlsxx28_3.5.18-1ubuntu1.1_armhf.deb Original-Maintainer: Debian GnuTLS Maintainers