- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Andreas Metzler
- Date:
- 2022-07-09 10:52:49 UTC
- Severity:
- normal
- Tags:
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian.org@packages.debian.org Usertags: pu X-Debbugs-Cc: Dmitry Baryshkov <dbaryshkov@gmail.com>, gnutls28@packages.debian.org Hello, as requested in #1011246 I would like fix miscalculation of SHA384 in the SSA accelarated implementation. It is a one-line change and was part of the 3.7.3 release. cu Andreas
On 2022-05-29 Andreas Metzler <ametzler@bebt.de> wrote: [...] [...] Actually this seems like a good opportunity to fix a minor CVE, which was also fixed in 3.7.3. cu Andreas
Please go ahead. Regards, Adam
package release.debian.org tags 1012033 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: gnutls28 Version: 3.7.1-5+deb11u1 Explanation: fix SSSE3 SHA384 miscalculation; fix null pointer deference issue [CVE-2021-4209]
package release.debian.org tags 1012033 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: gnutls28 Version: 3.7.1-5+deb11u1 Explanation: fix SSSE3 SHA384 miscalculation; fix null pointer deference issue [CVE-2021-4209]
(re-sending with fixed bug numbers) Hi, The updates discussed in these bugs were included in today's bullseye point release. Regards, Adam