-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 28 Aug 2021 13:52:11 +0200 Source: libssh Binary: libssh-4 libssh-4-dbgsym libssh-dev libssh-gcrypt-4 libssh-gcrypt-4-dbgsym libssh-gcrypt-dev Architecture: mipsel Version: 0.9.5-1+deb11u1 Distribution: bullseye-security Urgency: high Maintainer: mips64el Build Daemon (mipsel-osuosl-02) Changed-By: Martin Pitt Description: libssh-4 - tiny C SSH library (OpenSSL flavor) libssh-dev - tiny C SSH library - Development files (OpenSSL flavor) libssh-gcrypt-4 - tiny C SSH library (gcrypt flavor) libssh-gcrypt-dev - tiny C SSH library - Development files (gcrypt flavor) Closes: 993046 Changes: libssh (0.9.5-1+deb11u1) bullseye-security; urgency=high . * dh-gex: Avoid memory leaks. Add 0001-dh-gex-Avoid-memory-leaks.patch: Backported from upstream 0.9.6 release. * Fix handshake bug with AEAD ciphers and no HMAC overlap. Add 0002-Fix-handshake-bug-with-AEAD-ciphers-and-no-HMAC-over.patch and 0003-Add-initial-server-algorithm-test-for-no-HMAC-overla.patch: Backport fix and test from upstream 0.9.6 release. * Create a separate length for session_id. Add 0004-CVE-2021-3634-Create-a-separate-length-for-session_i.patch and 0005-tests-Simple-reproducer-for-rekeying-with-different-.patch: Backport fix and test from upstream 0.9.6 release. CVE-2021-3634 (Closes: #993046) Checksums-Sha1: a6f2716f08850d358b044adf6aa90275687d6ed1 465920 libssh-4-dbgsym_0.9.5-1+deb11u1_mipsel.deb a3ad5191d3b5f167c21090b29ff4a8b04929a8b2 164672 libssh-4_0.9.5-1+deb11u1_mipsel.deb 416b41d66f5cd311d1262a6c1544d6bacc9b90d8 250752 libssh-dev_0.9.5-1+deb11u1_mipsel.deb e4c2fcd3dc93ef647eadc3fdfe2defaf7bd24e62 507580 libssh-gcrypt-4-dbgsym_0.9.5-1+deb11u1_mipsel.deb 85a1a1f149f8f8242654801669cf4fd310805383 197020 libssh-gcrypt-4_0.9.5-1+deb11u1_mipsel.deb 7535753bb82a889871c3a04226b1c5add41e792a 286912 libssh-gcrypt-dev_0.9.5-1+deb11u1_mipsel.deb 521d1f3a5c73a9640580e0ae1287cf4c33ffd002 8766 libssh_0.9.5-1+deb11u1_mipsel-buildd.buildinfo Checksums-Sha256: b1e8804eff2c3537bab5c2a8245d6c286006e10cb67a865db37e86d157977c4a 465920 libssh-4-dbgsym_0.9.5-1+deb11u1_mipsel.deb 52ff26c8ba78664bbc2d1892928ac39050c6578ca2807c625f4259be8827eb13 164672 libssh-4_0.9.5-1+deb11u1_mipsel.deb a1e9382d3d880f654592143427f76c78c619442d0e4008892bf978145195465d 250752 libssh-dev_0.9.5-1+deb11u1_mipsel.deb 1016e044c23c180246b1ad88cde87c436056a4a81ef4a1c9f42a4cdee0334be7 507580 libssh-gcrypt-4-dbgsym_0.9.5-1+deb11u1_mipsel.deb 5c8d02889eb0750f16816408a3e8366f468b23b2b6bf2142facdaebb1fccb692 197020 libssh-gcrypt-4_0.9.5-1+deb11u1_mipsel.deb dbc7fe037448aac497364497fa333987735aeb3d1fb2126113d0e2d042383b42 286912 libssh-gcrypt-dev_0.9.5-1+deb11u1_mipsel.deb 5c1282e216be97b5332fcdd6552643232c701b95bb413bbe235a36e6971a0d31 8766 libssh_0.9.5-1+deb11u1_mipsel-buildd.buildinfo Files: e41d3c2872f5b64ed0e370fe9bbeeb77 465920 debug optional libssh-4-dbgsym_0.9.5-1+deb11u1_mipsel.deb 196a66ba388b37042b54a7995b8ba9e9 164672 libs optional libssh-4_0.9.5-1+deb11u1_mipsel.deb e453e85cb0ed567855c0b0e7573c206c 250752 libdevel optional libssh-dev_0.9.5-1+deb11u1_mipsel.deb de3c7f0335c9d19a4d79eb30976bc5f3 507580 debug optional libssh-gcrypt-4-dbgsym_0.9.5-1+deb11u1_mipsel.deb 6f335b2104407452710b22db88c6970a 197020 libs optional libssh-gcrypt-4_0.9.5-1+deb11u1_mipsel.deb 1bf9884e0a777facb7a64a8978d71440 286912 libdevel optional libssh-gcrypt-dev_0.9.5-1+deb11u1_mipsel.deb 94e1b46a1c9eb2bf5285a8307a82fc74 8766 libs optional libssh_0.9.5-1+deb11u1_mipsel-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE3MoVZ9ZwC61enleHma0LVKlb6LIFAmEsYtgACgkQma0LVKlb 6LLGLxAAkRmUIb1vO6EsWIvZFa9zd4SyiSXUE2rXFghzwBDJD6OxWA4RgKuluQda vo5Gr5fWfXTKFtpNoVvJFmrc1l6W2EJmrQkzj0Rwrbumo+s2v+Ae06pf6fvqXLw8 XC43d8cEkjbadLv0q0gvfSzQRcE5J2e0+fVxj+Oa1wNynWtx/Is4f0rzykpGFpvK V25SJgS31TLL0GtWiOofTxE9JM2o5AVYx3yP5xzZA4HveMDnDmGefqr+MHhoMfi7 bubS53C9ii8W8Pu12wBCrm8oB+wk9ZwI2ygRZRJBDjD6sIC2dNLik0Fnyez46kI5 y/IucNa3YKXeGuGeNM5KhCGRDy9Tt7gA8VQEwD3pJASZZP5WKlP1a24IMLYCWJWG FTRpooNq87alMgkhMxOsJImgB37pSO1JXIPeUGWQWtQZgz25cLO0DG7W6xTHNUrk HjTxBtmjHmENBg0BcoVrxpedP7r8cT0/w/jLo0ducdvbFo6aiIES5LG0ORSrpb5P t48M9HR8n9LeD/ZHr0sFRO1f6KEkAkKLSJUS7GL9aq8rNR3GdazaoFcSyez+EkJy Bf8Pzg74Fq9eHbKPmomTfZmBUxeYZBce7mf6H7x6zgxYzcqF1hORcFbIp149N6UZ Ny4hlI/8cZsUJbLakB4zOwC4Ezq0KkdmkWX6UbHguDxd7lrm6Lk= =E7N4 -----END PGP SIGNATURE-----