-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 11 Jun 2021 19:53:20 +0200 Source: nettle Binary: libhogweed4 libhogweed4-dbgsym libnettle6 libnettle6-dbgsym nettle-bin nettle-bin-dbgsym nettle-dev Architecture: amd64 Version: 3.4.1-1+deb10u1 Distribution: buster-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Magnus Holmgren Description: libhogweed4 - low level cryptographic library (public-key cryptos) libnettle6 - low level cryptographic library (symmetric and one-way cryptos) nettle-bin - low level cryptographic library (binary tools) nettle-dev - low level cryptographic library (development files) Closes: 985652 989631 Changes: nettle (3.4.1-1+deb10u1) buster-security; urgency=high . * Fix for CVE-2021-3580 - potential crash on invalid input to the RSA decryption functions (Closes: #989631). * Fix for CVE-2021-20305 - bug in ECDSA signature verification that could lead to a denial of service attack (via an assertion failure) or possibly incorrect results, backported from 3.7.2 by Marc Deslauriers (Closes: #985652). Checksums-Sha1: a6ae737c4a93341489247a48b59891b3a4150926 200680 libhogweed4-dbgsym_3.4.1-1+deb10u1_amd64.deb 4e48595e8f3e6582bdbe72f78ad344dfd6bb89db 140832 libhogweed4_3.4.1-1+deb10u1_amd64.deb 026b8c578a7354ab85604e5eef3bccd7aa5823ef 217912 libnettle6-dbgsym_3.4.1-1+deb10u1_amd64.deb d1b9d2b51798fcdc29072211f403fc65e311a5a1 214552 libnettle6_3.4.1-1+deb10u1_amd64.deb 9896491d97e8b84e4bd78a150b53211a7073a065 168652 nettle-bin-dbgsym_3.4.1-1+deb10u1_amd64.deb ce83a0862f81bee37d4031098bc53079df083bf3 25176 nettle-bin_3.4.1-1+deb10u1_amd64.deb 477bfae9bfcc1f8884d4c09184ea50eef090bfb1 1076708 nettle-dev_3.4.1-1+deb10u1_amd64.deb 3d1fd51f61c3bf77cfa6939ce484e9891f2c99e1 7318 nettle_3.4.1-1+deb10u1_amd64-buildd.buildinfo Checksums-Sha256: ca402a12b7f54f34337d124d8fd1cf308822dd4bafde2686f030faa0bb848eca 200680 libhogweed4-dbgsym_3.4.1-1+deb10u1_amd64.deb e57c058cfd9b6622dd595be4ee94e2aed595be8cbc8d0623db5fb4595f09cdd5 140832 libhogweed4_3.4.1-1+deb10u1_amd64.deb 079d7c1406b3b5333b50816358cd40252483f3c3c7360998bdc71c58ba887f2d 217912 libnettle6-dbgsym_3.4.1-1+deb10u1_amd64.deb e7139151367e9ee82bb7c1664ce5793f8aa9310492604726d0f535f969394bdf 214552 libnettle6_3.4.1-1+deb10u1_amd64.deb ad38e8d7590bea97ae5c85d1883d5bab085db6dcfe3d0a11f29f078485464359 168652 nettle-bin-dbgsym_3.4.1-1+deb10u1_amd64.deb b47b8abed25d792ccbec8ca8095cde5b10566aac0838b0280888d2b7dfc90247 25176 nettle-bin_3.4.1-1+deb10u1_amd64.deb 7bdfd37049861336262f1a3e454ba1f3abeb74c54b327c6dcffc3f9edd1f5561 1076708 nettle-dev_3.4.1-1+deb10u1_amd64.deb 49f57559362cb1981fca9169086b9becfb0a91386fc0ef87efed1364d619b5be 7318 nettle_3.4.1-1+deb10u1_amd64-buildd.buildinfo Files: 84f4230b161130b7dce50898be8be38e 200680 debug optional libhogweed4-dbgsym_3.4.1-1+deb10u1_amd64.deb c6863a90b2fcd1f7d417cf40bf6bbaa8 140832 libs optional libhogweed4_3.4.1-1+deb10u1_amd64.deb e421f1dce0312039aaf2e1bd18d4930c 217912 debug optional libnettle6-dbgsym_3.4.1-1+deb10u1_amd64.deb 10cc3b686c0d755cf643bd182dc02f76 214552 libs optional libnettle6_3.4.1-1+deb10u1_amd64.deb 176d607df5b7dd3d3e936018349a70ee 168652 debug optional nettle-bin-dbgsym_3.4.1-1+deb10u1_amd64.deb b790908835d17c7aea9b21e30937e860 25176 misc optional nettle-bin_3.4.1-1+deb10u1_amd64.deb 4ea9742c65e3f13585a3293167a9ae3d 1076708 libdevel optional nettle-dev_3.4.1-1+deb10u1_amd64.deb 3c4ae8ff4f956ffd17994d5e6b06c702 7318 libs optional nettle_3.4.1-1+deb10u1_amd64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEcU6S3GjxzS183/1jeHlhQ1ylJm8FAmDJHKIACgkQeHlhQ1yl Jm9fWxAAo50U2W4yb/MAL9YtGHVy/XYc0hxaVeqqPHNik91TkkLdK98WfangO3zf shAnorfhe/NdUPB0UQ5YNlMwCvOX8QAhx46DNkvkhXhEJBTLVTXZxaBqPiu8tD5c XQ8WqLWR84gN3lqggVEfl29o0NjrOuOliVV8bKPpfEK7pzNe1E6sm3qT9xCrySbf y+DjOJCddIdmqHsk7lToGnJDKtV/W4ZwpmXthdnb+mZ+DWHu+k/d6eOOYDK+XNzZ MfEIMWBmBDORZyYLQRQO2OHou+4BuVzAuwt9ozoCYwsYdo9sg9ooInsiPAhtZa13 viFIzycogVm7/VhsWQit8NYCxKuerdVu91jzCYXkHCwQo+p3Pq+SiPkgnhH74ewG fK9ibGpLt+FNUeMbVKeylNlrNtTBNiAG4heq8F5yUYzB1WC/vva9yvqdFkuTd+nD ZKUTKHbMAwry4eNA7ej3UJeSpZkpB8OPUV5jHOuSDx08XWDHAZoo6kgEe3Eg4VsW m6myfpa3omFc7Gv2pYxzzy44yCSr/hcTXvqNiah0Boftw6CQnqADw/VijOTigRaV BXaSbyeTgzpYVRuFh6Ve93V65dsUZ9CIZ5fmeRjePi5/5Z8FEuZ2HnwqNSJu5Xhz bg29lrn6FS9IsBiCqiooOI7+dNKX64b6a31usAeHwCJEsO8S/W8= =TpWQ -----END PGP SIGNATURE-----