-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 28 Aug 2021 13:52:11 +0200 Source: libssh Binary: libssh-4 libssh-4-dbgsym libssh-dev libssh-gcrypt-4 libssh-gcrypt-4-dbgsym libssh-gcrypt-dev Architecture: mips64el Version: 0.9.5-1+deb11u1 Distribution: bullseye-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-aql-03) Changed-By: Martin Pitt Description: libssh-4 - tiny C SSH library (OpenSSL flavor) libssh-dev - tiny C SSH library - Development files (OpenSSL flavor) libssh-gcrypt-4 - tiny C SSH library (gcrypt flavor) libssh-gcrypt-dev - tiny C SSH library - Development files (gcrypt flavor) Closes: 993046 Changes: libssh (0.9.5-1+deb11u1) bullseye-security; urgency=high . * dh-gex: Avoid memory leaks. Add 0001-dh-gex-Avoid-memory-leaks.patch: Backported from upstream 0.9.6 release. * Fix handshake bug with AEAD ciphers and no HMAC overlap. Add 0002-Fix-handshake-bug-with-AEAD-ciphers-and-no-HMAC-over.patch and 0003-Add-initial-server-algorithm-test-for-no-HMAC-overla.patch: Backport fix and test from upstream 0.9.6 release. * Create a separate length for session_id. Add 0004-CVE-2021-3634-Create-a-separate-length-for-session_i.patch and 0005-tests-Simple-reproducer-for-rekeying-with-different-.patch: Backport fix and test from upstream 0.9.6 release. CVE-2021-3634 (Closes: #993046) Checksums-Sha1: bb2691fec42626ccf39f10833de0c443c355dc55 498124 libssh-4-dbgsym_0.9.5-1+deb11u1_mips64el.deb 0391c253a819b5c588da3c9fb098076456c48977 162384 libssh-4_0.9.5-1+deb11u1_mips64el.deb 4339a942a6cb51c3fcb166b5a15d443103fc2035 251460 libssh-dev_0.9.5-1+deb11u1_mips64el.deb ddf52386252189226af1c199aec0f568721de86c 541092 libssh-gcrypt-4-dbgsym_0.9.5-1+deb11u1_mips64el.deb 37326a166b558f5c2c8b5f941309cbd922d75c6a 194748 libssh-gcrypt-4_0.9.5-1+deb11u1_mips64el.deb 1db6b88a7694a7bcc62b37298155aad713589cc1 289952 libssh-gcrypt-dev_0.9.5-1+deb11u1_mips64el.deb 79912d31372283df13c7cf198727a6fc2c95c440 8813 libssh_0.9.5-1+deb11u1_mips64el-buildd.buildinfo Checksums-Sha256: fb35758ccd27d26ca72a7328318856ae1be7c08ee4a261044c9022b32b6c2c22 498124 libssh-4-dbgsym_0.9.5-1+deb11u1_mips64el.deb 889e5fdecba51c5d7e9eb75f1a48782079eec33e9b54ff9daf6448f08fe45cb2 162384 libssh-4_0.9.5-1+deb11u1_mips64el.deb 7285b77d8f998ea43878531e710245131382bcd9d00f1143d8edf057feea422c 251460 libssh-dev_0.9.5-1+deb11u1_mips64el.deb 7f50e719abce791e6400057ad1827d4b1e06ee34a457bcc95bdf6fef623f94d8 541092 libssh-gcrypt-4-dbgsym_0.9.5-1+deb11u1_mips64el.deb b082c1bd516d6ce5d4563e7058b359ae50888f630ad976b7bc70f37bb75caae3 194748 libssh-gcrypt-4_0.9.5-1+deb11u1_mips64el.deb aa4a5e82f05f213141014bc68c2916c83944338c9be6f935a9ceec632c1a7f06 289952 libssh-gcrypt-dev_0.9.5-1+deb11u1_mips64el.deb 43f9719fcfef25ed2c499343311d32084e9940e1fdfb3b83208ba708e9feefae 8813 libssh_0.9.5-1+deb11u1_mips64el-buildd.buildinfo Files: 35932f81294bd2ac91f930b0609384e4 498124 debug optional libssh-4-dbgsym_0.9.5-1+deb11u1_mips64el.deb 30037912f2d49f37bef475a63ae64725 162384 libs optional libssh-4_0.9.5-1+deb11u1_mips64el.deb 6c997dd871625e4c2975e6cd2d9f171f 251460 libdevel optional libssh-dev_0.9.5-1+deb11u1_mips64el.deb 04fb3cb3c245b02dc1cdbc8911332a74 541092 debug optional libssh-gcrypt-4-dbgsym_0.9.5-1+deb11u1_mips64el.deb d0bacfdad40e30b66b708166e0b21968 194748 libs optional libssh-gcrypt-4_0.9.5-1+deb11u1_mips64el.deb bd16166dc27e9cf6ba59c580b943563b 289952 libdevel optional libssh-gcrypt-dev_0.9.5-1+deb11u1_mips64el.deb a3069404dab2a2790cd683a60ffb6dc7 8813 libs optional libssh_0.9.5-1+deb11u1_mips64el-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE6YhmUaQdOAULQQfkuEloAOY175IFAmEsYC4ACgkQuEloAOY1 75K3eRAAkjdgy2H8nH7rQ0Kn+iLNSALi4HZbydshWlAtd2axwubZja1uRbPMCOM4 XFAo4K+DrDZXmM0uLRu5P87Tp544fwGO3UXeQOUY8lAHWK7zjN4J+6R3GfKwMRz7 69edTsMauFeJ4GxoUrG059CzY4s3cuaegerah9eyQIbgg1/a4fFEU13w2Fh+odXL FgVwypidQ/4rV5p/UB9tF8IbUVJWReygYlwTEm/UA+3dLnfSmDnST0InHle0rHL9 pX2b8dNGOaF9FFImVxDO8KhVjKmL9zgB4EkSndeba2GTs1fD5k+/58gIBPnMkTfo /Pw9FzRrR2y2wW1yKnkV4exO8VWPW7F2T6u2cvbhwaFUQot4EfIRkDSJf2fyunEr lLh7ONzVW77C8WbncsBn4khLUVqrFEiSIUcTCaKVeTzC25Ffz/zpMua7lTeb3TNk 5Z3o2I/IX5mpTmCyGy9QbW9g++S0BamTxVgtXGaMmSvk50QsvPZgGi33KzSsaNX5 xBGIPF2LU9JSRodmcZXF9u+suBXjcUnartytEm1N4rBeek4wOBU7N4lVUYuU5n3L YPYwkzyj0tUIg80UMJtNWFw/SG/8roiYAhPy4bIKXlV0vpAYYY5G6xmgG5Z+ClJB hhHQa82kuT8Hsoj1IhDjA1i4KqMiUsHx2FKoI8cICE5/jxkEK2w= =JDEs -----END PGP SIGNATURE-----