-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 11 Jun 2021 19:53:20 +0200 Source: nettle Binary: libhogweed4 libhogweed4-dbgsym libnettle6 libnettle6-dbgsym nettle-bin nettle-bin-dbgsym nettle-dev Architecture: ppc64el Version: 3.4.1-1+deb10u1 Distribution: buster-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-osuosl-01) Changed-By: Magnus Holmgren Description: libhogweed4 - low level cryptographic library (public-key cryptos) libnettle6 - low level cryptographic library (symmetric and one-way cryptos) nettle-bin - low level cryptographic library (binary tools) nettle-dev - low level cryptographic library (development files) Closes: 985652 989631 Changes: nettle (3.4.1-1+deb10u1) buster-security; urgency=high . * Fix for CVE-2021-3580 - potential crash on invalid input to the RSA decryption functions (Closes: #989631). * Fix for CVE-2021-20305 - bug in ECDSA signature verification that could lead to a denial of service attack (via an assertion failure) or possibly incorrect results, backported from 3.7.2 by Marc Deslauriers (Closes: #985652). Checksums-Sha1: 39e25d8bd1bee5470bd87fb29b0a2581f7ddf28b 201596 libhogweed4-dbgsym_3.4.1-1+deb10u1_ppc64el.deb bfe903d53348ae46b4b47a123a0c4090d80f451b 143888 libhogweed4_3.4.1-1+deb10u1_ppc64el.deb e422f9da309a6959d2bd2437171fae6f5f7c0593 250048 libnettle6-dbgsym_3.4.1-1+deb10u1_ppc64el.deb 052060b58f88076df3adf9149aa4e34c92e0e416 238044 libnettle6_3.4.1-1+deb10u1_ppc64el.deb e38dd3caa8d99e9b71f103a93c7654bdedde6692 172828 nettle-bin-dbgsym_3.4.1-1+deb10u1_ppc64el.deb a95db904a4a957c7f6c6e67ee0674f5c4797a640 27056 nettle-bin_3.4.1-1+deb10u1_ppc64el.deb 80b035565c1582157c37386e6937087ae4d48dfb 1108856 nettle-dev_3.4.1-1+deb10u1_ppc64el.deb 6537c533c3ace587299b249a5e041001fc7e1fb2 7347 nettle_3.4.1-1+deb10u1_ppc64el-buildd.buildinfo Checksums-Sha256: 5815fb7a27591a3ce372905ae94b75975ecc6f9d4434d7cd3b4f7ddc502351bd 201596 libhogweed4-dbgsym_3.4.1-1+deb10u1_ppc64el.deb 520335c4009ab8f5dbb5b21d9f7b4ffd0844116e280525bd3a4aa1dffc191088 143888 libhogweed4_3.4.1-1+deb10u1_ppc64el.deb 591e4859a287fc32565e61c5b05ec950904b174a7de3440d7335401364514ff9 250048 libnettle6-dbgsym_3.4.1-1+deb10u1_ppc64el.deb cbc76fb0dce2ea9c926f1c3880486b4fdd5d8673575e7dfffe1688397e15e55a 238044 libnettle6_3.4.1-1+deb10u1_ppc64el.deb d6ec8f7f3ca2e2acc0b17511ce853849c5a3dbddc9b18ec77778c37be0758357 172828 nettle-bin-dbgsym_3.4.1-1+deb10u1_ppc64el.deb d8e60a7f1db42d7ce890029799c74a541b53219a8d8ed464ddfec1923684d0e6 27056 nettle-bin_3.4.1-1+deb10u1_ppc64el.deb d788c0e5768a370c8624f04100c49077ae45267ab2a04c8c4264397f67efc62f 1108856 nettle-dev_3.4.1-1+deb10u1_ppc64el.deb c3c08373f18a6543b09cc7ac8259ac41965453fba4de8b89ded4daa5715c5acc 7347 nettle_3.4.1-1+deb10u1_ppc64el-buildd.buildinfo Files: a0a32f238f5330913c712f28e4fee151 201596 debug optional libhogweed4-dbgsym_3.4.1-1+deb10u1_ppc64el.deb aad9fada20af115b4c00394ab8d8108d 143888 libs optional libhogweed4_3.4.1-1+deb10u1_ppc64el.deb 603c4e59277941f3dca4183815c735ae 250048 debug optional libnettle6-dbgsym_3.4.1-1+deb10u1_ppc64el.deb 2d0e20198717224b3ae1e21520bc02dc 238044 libs optional libnettle6_3.4.1-1+deb10u1_ppc64el.deb 9d9094f15b78574fa120f523143f2f4f 172828 debug optional nettle-bin-dbgsym_3.4.1-1+deb10u1_ppc64el.deb 5fe583e3b5e2511e89ccced84b2c2cc7 27056 misc optional nettle-bin_3.4.1-1+deb10u1_ppc64el.deb 21b7255043dd9be1c78011c4624b51ae 1108856 libdevel optional nettle-dev_3.4.1-1+deb10u1_ppc64el.deb 91d26f73558e7dd93274f0335f753e2c 7347 libs optional nettle_3.4.1-1+deb10u1_ppc64el-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEyl4agJ4TauxiSNGQursC4Iy2jF0FAmDJHZ4ACgkQursC4Iy2 jF0JJw//Tn/681hkxAdYOYaMRmht89CbvsvjdmsPtDGNRL9OOQcAHs+DF28/S+pG hXh4YNB5JH4W8Cfhn89/nhQWxlUSjQ0K7eoNC5SL8ZaIP6vllZEHhSmrcvxWZpzp RK3P+WS15n0/0wgToa9EXlvTCMUOstr+Q9PF4uatLLtkLxWAd3cHxZQUfXJAnmji fclGBTscvzLDvzzlDJJ9zgT6mLGIXrutMD/8TKvsf7NoFPkol28dnt6585yKJRYi sL0GgtU5NE4DgrY2YLCqhvvUWkc8s0+9/u+bp9/j6Nds4tVu6xgaW0mHyMad18t7 O2YRGKI9Ux9b+aZt0SdQw1CfF/MyQcYmxloYyOymsMTxlASMqJkVnQ147FIvxesa KV0eTs8BJ1Tawjt8AyElACNnMXVaXf4b1cm4IZtj1B6V8yzBhqvhkoMBkGLgkONi iiwdZ4UVHhSD3mGgemIPuugFZAyhckE80AdeaoQhTVZqphA37e7KHcl9xyL20eky zEkWWPzv+4zVIKjvKlXD8vudwKj5dxtoHyxuwI8W+f0rKCoQofZuY2Ig8Wtrxbtt WKNQb9fKU4yHTAYQ4L/suNQlWjH0c6rOTH5wOP1rJArPH+hrmhnCcWRhH7e5p0fm ootTqTY/imqt+lryYF9Yx8QaLL/Q08PfZbYdQpX8xWAlOqgcnt4= =Qb8P -----END PGP SIGNATURE-----