-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 3.0 (quilt) Source: gnutls28 Binary: libgnutls28-dev, libgnutls-deb0-28, libgnutls28-dbg, gnutls-bin, gnutls-doc, guile-gnutls, libgnutlsxx28, libgnutls-openssl27 Architecture: any all Version: 3.3.8-6+deb8u1 Maintainer: Debian GnuTLS Maintainers <[email protected]> Uploaders: Andreas Metzler <[email protected]>, Eric Dorland <[email protected]>, James Westby <[email protected]>, Simon Josefsson <[email protected]> Homepage: http://www.gnutls.org/ Standards-Version: 3.9.5 Vcs-Browser: http://anonscm.debian.org/gitweb/?p=pkg-gnutls/gnutls.git Vcs-Git: git://anonscm.debian.org/pkg-gnutls/gnutls.git Build-Depends: debhelper (>= 9), nettle-dev (>= 2.7), zlib1g-dev, libtasn1-6-dev (>= 3.9), autotools-dev, guile-2.0-dev [!ia64 !m68k], datefudge, libp11-kit-dev (>= 0.20.7), pkg-config, chrpath, libidn11-dev, autogen (>= 1:5.16-0), bison, dh-autoreconf, libgmp-dev (>= 2:6), libopts25-dev Build-Depends-Indep: gtk-doc-tools, texinfo (>= 4.8) Build-Conflicts: libgnutls-dev, libp11-kit-dev (= 0.21.2-1) Package-List: gnutls-bin deb net optional arch=any gnutls-doc deb doc optional arch=all guile-gnutls deb lisp optional arch=amd64,arm64,armel,armhf,i386,kfreebsd-amd64,kfreebsd-i386,mips,mipsel,powerpc,ppc64el,s390,s390x,sparc,hurd-i386 libgnutls-deb0-28 deb libs standard arch=any libgnutls-openssl27 deb libs standard arch=any libgnutls28-dbg deb debug extra arch=any libgnutls28-dev deb libdevel optional arch=any libgnutlsxx28 deb libs extra arch=any Checksums-Sha1: 2c07ed3f0ec3284820985085d63311e8b73cb48f 6153180 gnutls28_3.3.8.orig.tar.xz 40a46a3babc277c1f62e43624fd290ab63e5bebf 90332 gnutls28_3.3.8-6+deb8u1.debian.tar.xz Checksums-Sha256: bd4642f180e19632f4ed3a1e62d60c824c7b695f5cddf41a8fba1b272eaef046 6153180 gnutls28_3.3.8.orig.tar.xz 2d71ec37eb28701e27d356ccdd4d1c0cd7f1670710b351c032bf0622fc48e0ab 90332 gnutls28_3.3.8-6+deb8u1.debian.tar.xz Files: b57e6b7630bdba9ea8eb28ff0eb29c2f 6153180 gnutls28_3.3.8.orig.tar.xz 160c6aae89777b3c8750e83ec58b8d2c 90332 gnutls28_3.3.8-6+deb8u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJVQQwsAAoJEKVPAYVDghSE4+YP/icxBhNIJERAoFXqngEvH9TW vpHD+0R7yWBBLlEnXRuipRlS1xFZXGAKES4AjLLguFrgEfBZRErSiQ4lwWrd+1Ym y9IycEsyau0hpagJmeKhtrrih2jsk/yebuzbZomYdL914wBMGnp5AFI/IH66olyM +8pCQCX0KntiWnZ7yv0fOctHKJ87XMYQtEjlCAEFdQ3gLIfVih9TdBlJIeKxa/IS SkQoI2rxgAeHzf1UuuDa6aT7pYURWec5ULxFuxoeuYDgcI6Z9c/O2cyCsn6TeQXY HNIjknbRB9reNWCfFmjUMCItja+UkCpaR3qhj3g+4qwBYDMlo2TvaGVL5i5wmXam 2hpXUphFW9vsW7lVBKE+3eNfjs3rrhvbATyquZ/nnY2lJoUtqmOksUu2kGvxr7o7 b8JeJNvnAkNguDacEmECTXv8k42vOzeGR0s3bYpZ8R+zyK/q7RTpKjxChGkP/o7l 5Xtj3cgbl/322DruIYXxdRGarZP04AjdFnF1XUzOB3eHOFqbDdr0mvDNEk5cFYJ4 Szz9/xR89GcJHMx9kucSLlAXdGELUpXfO1d0EKVt3kgmCMaixXG05EgKDiqR+cPk G8V2DikuKgW3b2qj/1w25KzwNXiMyuYDgXPgmExevW1TDlkUkWJkJV7C8BnAS2JH IpiE71Fnlel0WBoyF31t =1ill -----END PGP SIGNATURE----- Changes: gnutls28 (3.3.8-6+deb8u1) jessie; urgency=medium * Reupload 3.3.8-7 unchanged for first point release: 45_eliminated-double-free.diff 46_Better-fix-for-the-double-free.diff: Pull two patches from upstream to a use-after-free flaw in gnutls_x509_ext_import_crl_dist_points(). CVE-2015-3308 Closes: #782776 -- Andreas Metzler <[email protected]> Mon, 27 Apr 2015 19:38:26 +0200