-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 28 Aug 2021 13:52:11 +0200 Source: libssh Binary: libssh-4 libssh-4-dbgsym libssh-dev libssh-gcrypt-4 libssh-gcrypt-4-dbgsym libssh-gcrypt-dev Architecture: ppc64el Version: 0.9.5-1+deb11u1 Distribution: bullseye-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-osuosl-01) Changed-By: Martin Pitt Description: libssh-4 - tiny C SSH library (OpenSSL flavor) libssh-dev - tiny C SSH library - Development files (OpenSSL flavor) libssh-gcrypt-4 - tiny C SSH library (gcrypt flavor) libssh-gcrypt-dev - tiny C SSH library - Development files (gcrypt flavor) Closes: 993046 Changes: libssh (0.9.5-1+deb11u1) bullseye-security; urgency=high . * dh-gex: Avoid memory leaks. Add 0001-dh-gex-Avoid-memory-leaks.patch: Backported from upstream 0.9.6 release. * Fix handshake bug with AEAD ciphers and no HMAC overlap. Add 0002-Fix-handshake-bug-with-AEAD-ciphers-and-no-HMAC-over.patch and 0003-Add-initial-server-algorithm-test-for-no-HMAC-overla.patch: Backport fix and test from upstream 0.9.6 release. * Create a separate length for session_id. Add 0004-CVE-2021-3634-Create-a-separate-length-for-session_i.patch and 0005-tests-Simple-reproducer-for-rekeying-with-different-.patch: Backport fix and test from upstream 0.9.6 release. CVE-2021-3634 (Closes: #993046) Checksums-Sha1: 9c906878dda36c25697ebd10a6934a9d89696f16 489428 libssh-4-dbgsym_0.9.5-1+deb11u1_ppc64el.deb 4b84fd7e05a34bf9706b9bd426c0fd3861aa5d9b 202240 libssh-4_0.9.5-1+deb11u1_ppc64el.deb 49a4d31ff7c51a34b47811bf559c456751c1446f 258988 libssh-dev_0.9.5-1+deb11u1_ppc64el.deb 700cfd4927b413467d3e2799dfd275acd236bd1d 530620 libssh-gcrypt-4-dbgsym_0.9.5-1+deb11u1_ppc64el.deb e05bd3f5cb0e8679b72352795c7045be3554630e 235396 libssh-gcrypt-4_0.9.5-1+deb11u1_ppc64el.deb 8ae3717fa9e1e99ac28cc96ee04e591a5a6182e3 295680 libssh-gcrypt-dev_0.9.5-1+deb11u1_ppc64el.deb 54c271bc0201b0174c430724c6ed6d5f7775c08a 8961 libssh_0.9.5-1+deb11u1_ppc64el-buildd.buildinfo Checksums-Sha256: 20be8dff88124216b1effa7af1f904cd8d228d8301ee8e00a087a7897d0e49ef 489428 libssh-4-dbgsym_0.9.5-1+deb11u1_ppc64el.deb 2c8dfaa16c5fdfd41a48bff8f217bdeedbc6c684b43c162d222c8e551878025a 202240 libssh-4_0.9.5-1+deb11u1_ppc64el.deb 3f7cb694acb3578345d26e543e72696ee57e5d9e21c7f09ab25a9f4f8737e0e9 258988 libssh-dev_0.9.5-1+deb11u1_ppc64el.deb dfe1890b03301a7e2eafa599083ce2f02963ec0b908568b8de1cdbfd49ac1876 530620 libssh-gcrypt-4-dbgsym_0.9.5-1+deb11u1_ppc64el.deb 7ba5669c43f1fb10ad944915101072100e7fec336d92fcd1c71a51ad69fa2755 235396 libssh-gcrypt-4_0.9.5-1+deb11u1_ppc64el.deb 6811b37b4ef981d2da43b0b090c816f34bf8511907872eaed54f0661292f43c4 295680 libssh-gcrypt-dev_0.9.5-1+deb11u1_ppc64el.deb 75b28276a6c8785f5f75e69e0048690a24351311cde59147077a9b3e51359f19 8961 libssh_0.9.5-1+deb11u1_ppc64el-buildd.buildinfo Files: d8cf7d85f90cf9f66c7fdb39b925e58c 489428 debug optional libssh-4-dbgsym_0.9.5-1+deb11u1_ppc64el.deb 701021ef307993964b990fa783845e4a 202240 libs optional libssh-4_0.9.5-1+deb11u1_ppc64el.deb 107d7edcd9df153dfeca16082e38f3bd 258988 libdevel optional libssh-dev_0.9.5-1+deb11u1_ppc64el.deb 27a0c17ab1866ae477471226daac6ae2 530620 debug optional libssh-gcrypt-4-dbgsym_0.9.5-1+deb11u1_ppc64el.deb 375dc35448dd6b2900f6b0d7b64df8de 235396 libs optional libssh-gcrypt-4_0.9.5-1+deb11u1_ppc64el.deb 2e9c4bec0e77f7f2adeea0328390b8a4 295680 libdevel optional libssh-gcrypt-dev_0.9.5-1+deb11u1_ppc64el.deb 8351b45c5668218be5307599f4fd9cc2 8961 libs optional libssh_0.9.5-1+deb11u1_ppc64el-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEzxcBZLbWYROS8SGLQ0vh8H8HxvwFAmEsWdQACgkQQ0vh8H8H xvxZIhAArxZGHpIZkC/Yjf9cxE6I8zt6Fizf3zkbf6ywZmObOW1N47Z5LIvF0wS5 XS5lyXYwjiDQRNqEtmNDc7F0f+cZEL/oY0mUVcpFFx2vUvOXqhGXmWvwh4O9r/V6 jQ/n/dIuqCl/sxGreIkAZeoxC4iWNucsSuua4alkJTQAyzZdInJam4pOCcca6M06 VZjTGwA9VG7rN59qAEA1rVyhFo861V1VoYiYKQVGvOhltdrSuXKIKfts53v0F8PG D5WHnKk+bFej61z9FanNu+Y3/jaaD258CtsQK26pCuAhcCmt+GHbDwlYtR0tqThg wJ6W9teqrKmWLUqkCVInxrSJEkmAwJ6GVppeuTRtM+PzuvUwWJ4jQqM1kN2Hpqjm 7ToLk/k70k/rS6By5q1nUtiAPNnHJqGN2MBfTXe933nZ1tMs80NBxSJViPWWprP+ urc3mpxLP6uwo8tnWQBpSj+OaxidSibC1iTqnuNIUvv/KivHWsVsb5bsO06N3tiU Bc77WJUcqq4XQ95MwPCJAbbdcHMuJ+cpPxIsCdZiCZPdbtTOoEo7I2XX3rBni9z3 ikkwXSuPLP+oVhDB5po5lIaS8g+clnx83z13UpBfEoQqNNS1+zAOlDvIJG4JAROz gX76z+eIxNYjmuJAZSoyYmxejhZD9y7dodlUv8GaoJS0DmD9lH8= =/0lc -----END PGP SIGNATURE-----