-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 10 Feb 2025 10:07:24 +0100 Source: gnutls28 Binary: gnutls-bin gnutls-bin-dbgsym guile-gnutls guile-gnutls-dbgsym libgnutls-dane0 libgnutls-dane0-dbgsym libgnutls-openssl27 libgnutls-openssl27-dbgsym libgnutls28-dev libgnutls30 libgnutls30-dbgsym libgnutlsxx30 libgnutlsxx30-dbgsym Architecture: arm64 Version: 3.7.9-2+deb12u4 Distribution: bookworm-security Urgency: medium Maintainer: arm Build Daemon (arm-conova-02) Changed-By: Andreas Metzler Description: gnutls-bin - GNU TLS library - commandline utilities guile-gnutls - GNU TLS library - GNU Guile bindings libgnutls-dane0 - GNU TLS library - DANE security support libgnutls-openssl27 - GNU TLS library - OpenSSL wrapper libgnutls28-dev - GNU TLS library - development files libgnutls30 - GNU TLS library - main runtime library libgnutlsxx30 - GNU TLS library - C++ runtime library Changes: gnutls28 (3.7.9-2+deb12u4) bookworm-security; urgency=medium . * libgnutls: Fix potential DoS in handling certificates with numerous name constraints, as a follow-up of CVE-2024-12133 in libtasn1. Patch cherry-picked from 3.8.9 release. [GNUTLS-SA-2025-02-07, CVSS: medium] [CVE-2024-12243] Checksums-Sha1: e71466a27a87819d5e503d0e2de6c7cd42740746 901724 gnutls-bin-dbgsym_3.7.9-2+deb12u4_arm64.deb b50bfb70e22d210dcb9f3ab757d3d8f4405beb15 623604 gnutls-bin_3.7.9-2+deb12u4_arm64.deb 143bcd996facc57e725b889521518661920e55a2 11266 gnutls28_3.7.9-2+deb12u4_arm64-buildd.buildinfo eb4ce7339d893603be2abbf4fcfac6eddc712d4a 257288 guile-gnutls-dbgsym_3.7.9-2+deb12u4_arm64.deb 9a71271cd9355147b43a1f985f5bab2fc4772899 456660 guile-gnutls_3.7.9-2+deb12u4_arm64.deb 92859f7fbe23164da35905be3f14fa2b9622443e 90160 libgnutls-dane0-dbgsym_3.7.9-2+deb12u4_arm64.deb 14023907098db47609c2595b00666b1f27159bd4 404060 libgnutls-dane0_3.7.9-2+deb12u4_arm64.deb 1319e909256ba57cfc3c492e960ea0d7056067b8 90764 libgnutls-openssl27-dbgsym_3.7.9-2+deb12u4_arm64.deb a3aea9d92ce87b442ca03f2caeae69d006fc9e10 404064 libgnutls-openssl27_3.7.9-2+deb12u4_arm64.deb da25ea54f7639482894bd740ee5c41a3490a61c1 1359272 libgnutls28-dev_3.7.9-2+deb12u4_arm64.deb 12a6fc2d12f0617c3ded1401b3c733db9333ab16 2097488 libgnutls30-dbgsym_3.7.9-2+deb12u4_arm64.deb 0024aba00aea167d26e597f790125e2c35681b5d 1313084 libgnutls30_3.7.9-2+deb12u4_arm64.deb b9214da81a92f63a1427b3c1568999736e23060e 48340 libgnutlsxx30-dbgsym_3.7.9-2+deb12u4_arm64.deb a7ab28d31a625e2d5f85fe534d727b00747e6273 13092 libgnutlsxx30_3.7.9-2+deb12u4_arm64.deb Checksums-Sha256: 568646f7144dcd01a8a8cf37e11bdaf980d268ff605af07bacaf64f3838bbb10 901724 gnutls-bin-dbgsym_3.7.9-2+deb12u4_arm64.deb b576988a6d87797fa41dd0aa3c908122fe64bd40d46ada45a6872ca8ef21c9f5 623604 gnutls-bin_3.7.9-2+deb12u4_arm64.deb bf30b928591ed3e4f2238a4de755536dca26fb1799914bca657f2829ac9660a5 11266 gnutls28_3.7.9-2+deb12u4_arm64-buildd.buildinfo 6abbad16a2ec5bf4ff45ed833378dee4fc9c89ae2b1c235878abdfe09aea5bd7 257288 guile-gnutls-dbgsym_3.7.9-2+deb12u4_arm64.deb d3fed2aa66d94eec052d6e057b2cb18d07226b274d0feddfb38ce38db269b3ce 456660 guile-gnutls_3.7.9-2+deb12u4_arm64.deb b8c1367d5c141292ba37e97bf783a78b6a3f6954c8b135c2b79a2b599fc0269d 90160 libgnutls-dane0-dbgsym_3.7.9-2+deb12u4_arm64.deb e310325d4f3f2e031397f43db9f786336f671a855b7457e2574c776098ea59d8 404060 libgnutls-dane0_3.7.9-2+deb12u4_arm64.deb 309ded2ff73c9916690dd2dd74ff7067f18c0454513038d1b3cf1acf392d52e9 90764 libgnutls-openssl27-dbgsym_3.7.9-2+deb12u4_arm64.deb 4fc3536903a7015e168f9c247ca865ef5208525407cc5133b4f29d8b2efec0cb 404064 libgnutls-openssl27_3.7.9-2+deb12u4_arm64.deb 181819b76a7ac17b6105ad2e4ed0ed736d055c864b5ffafd63770087c0b75c39 1359272 libgnutls28-dev_3.7.9-2+deb12u4_arm64.deb 34d5da30427f43f17aa0afb3ca628d0eb3840309e1a6a097798c47da5d08cb03 2097488 libgnutls30-dbgsym_3.7.9-2+deb12u4_arm64.deb 969fd8e77ee6e481a649c802d572107758ea6bb6d68467fce2068f3de12a21cd 1313084 libgnutls30_3.7.9-2+deb12u4_arm64.deb 6a177e2e5e5f1b6f11ff94effbc13d65b9db988ff898f386dde967cde5b4b004 48340 libgnutlsxx30-dbgsym_3.7.9-2+deb12u4_arm64.deb 45f643d480e05bb2f3ac5346e46062632f18f95965bb7cfd7bdb6159a25c4c33 13092 libgnutlsxx30_3.7.9-2+deb12u4_arm64.deb Files: 10012cd884a3ec5c682756a3b34309a7 901724 debug optional gnutls-bin-dbgsym_3.7.9-2+deb12u4_arm64.deb 58fbb35a21aeb465f3349bfa9a78a1d3 623604 net optional gnutls-bin_3.7.9-2+deb12u4_arm64.deb 29cb55bcea748fb06128016e534c3fab 11266 libs optional gnutls28_3.7.9-2+deb12u4_arm64-buildd.buildinfo b8ee669bb24a85af0e70e659905b779b 257288 debug optional guile-gnutls-dbgsym_3.7.9-2+deb12u4_arm64.deb 2ed08e2af6e66df9aecd6bc58acec4a6 456660 lisp optional guile-gnutls_3.7.9-2+deb12u4_arm64.deb 2ec5d1550a5716f541b25438adf049a4 90160 debug optional libgnutls-dane0-dbgsym_3.7.9-2+deb12u4_arm64.deb 58c7bcb73c4e2d5b2016191f919dae43 404060 libs optional libgnutls-dane0_3.7.9-2+deb12u4_arm64.deb 3b24a6ef99047425ee5103ec8e85978e 90764 debug optional libgnutls-openssl27-dbgsym_3.7.9-2+deb12u4_arm64.deb 99e0732d46e898d31cc309152769d33a 404064 libs optional libgnutls-openssl27_3.7.9-2+deb12u4_arm64.deb c26463160e9bd9ccc0797386bf443c28 1359272 libdevel optional libgnutls28-dev_3.7.9-2+deb12u4_arm64.deb 4dbce6b984591f09b8e25b96b448484e 2097488 debug optional libgnutls30-dbgsym_3.7.9-2+deb12u4_arm64.deb 884a91b1abcd38c42fa9a2ec4f8ccea4 1313084 libs optional libgnutls30_3.7.9-2+deb12u4_arm64.deb 11f3624559f57328d24e5aed024d552c 48340 debug optional libgnutlsxx30-dbgsym_3.7.9-2+deb12u4_arm64.deb b4e2f98da0d80f19338beaa68feed85b 13092 libs optional libgnutlsxx30_3.7.9-2+deb12u4_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKAzExpjGvTI78ZO8LARVyvnD3xkFAmetBQcACgkQLARVyvnD 3xnTfxAAk+JsX8ZswjflbUvKSaxsI1vdUFQMb3QY5SnE4U9nX3WIO8Az65EXHxpV pkwEL7UjwWZUfR4SbOD+AB3a+63VIcZwaamPsXp1hjk7+PiNPG71ULYY2V1pbfCK iT73kFCaA1tv/+WL0nAiKSvKD+fTS+Pbv1Oo1sy03V9rHOT8rqUyr8neVfaCBZ6I wX4hsr/jkfr5qerlv1DbanCHGu6AaztGOV72ly9A8s1OTdtfKBbBwVq8ljqRzbpG vme78oPO/6cM6DYERN2blXz0Wiy2PtBxP4p6WslwbzXepoKoMYEmyJnGyOtZBqk4 ezCfZRpD7fD4pbgmKa8cJptlSfXmN0JezvwPwZGcta8caHtQsrRn8ycB90yjS9oS QK9ApiyaFNjynsB0lWzM3ZNn0NFrVfOQzIShYg/O6yt75m7vkgFT9oZTldJYSgq1 vKuiBBiWyHOFwATafnLzzquWfE14NeVUYXeGrZQvwXNMg3A93F2yM0KS60+50z7p rYP1s5wkqB/YkOQNOICTxwtbkSiHTMrx9Vnhf3KSQtCB4n+GHqcAvVH8gzLFw8/w vpjh2bemlvF47Lgjt5PjW9lgGr4ic807fsSVqCCqM6bFyg1w8/s89DZ0FBzHQ5dm VZqYT+4qsxvZ/xw5tmOl4g2SWUhe4yKVHJRVHvKUE+QckrQTAbQ= =FWlP -----END PGP SIGNATURE-----