-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 29 Dec 2020 15:48:30 +0100 Source: p11-kit Binary: libp11-kit-dev libp11-kit0 libp11-kit0-dbgsym p11-kit p11-kit-dbgsym p11-kit-modules p11-kit-modules-dbgsym Architecture: armhf Version: 0.23.15-2+deb10u1 Distribution: buster-security Urgency: high Maintainer: arm Build Daemon (arm-ubc-06) Changed-By: Salvatore Bonaccorso Description: libp11-kit-dev - library for loading and coordinating access to PKCS#11 modules - libp11-kit0 - library for loading and coordinating access to PKCS#11 modules - p11-kit - p11-glue utilities p11-kit-modules - p11-glue proxy and trust modules Changes: p11-kit (0.23.15-2+deb10u1) buster-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix bounds check in p11_rpc_buffer_get_byte_array (CVE-2020-29362) * Check attribute length against buffer size (CVE-2020-29363) * Check for arithmetic overflows before allocating (CVE-2020-29361) * Follow-up to arithmetic overflow fix (CVE-2020-29361) Checksums-Sha1: 43fd0bf1f369d4b34a4d6b89f9998090418e58d7 195652 libp11-kit-dev_0.23.15-2+deb10u1_armhf.deb c1ef6b34663a237fada1bba06eff3c9e826365fc 1224940 libp11-kit0-dbgsym_0.23.15-2+deb10u1_armhf.deb c6022fcf154981a0198bae18822bbc188167efb6 292300 libp11-kit0_0.23.15-2+deb10u1_armhf.deb e9f11d9fb94e2099cd6ee118477ee62f2676e72a 297736 p11-kit-dbgsym_0.23.15-2+deb10u1_armhf.deb 5fb1fa704e4218a8726b1595138321468553d86a 1366268 p11-kit-modules-dbgsym_0.23.15-2+deb10u1_armhf.deb d730a953eb06148bc3de5955035763e20307513a 192136 p11-kit-modules_0.23.15-2+deb10u1_armhf.deb 0eb45efdcc2dad59b280c68343d019109005bb4f 8144 p11-kit_0.23.15-2+deb10u1_armhf-buildd.buildinfo eea80c909c312039b9b36deacbca57ffc8d9be8c 256476 p11-kit_0.23.15-2+deb10u1_armhf.deb Checksums-Sha256: cce72aad016eedd18cb509ed32e359a2b529680dfec7b19dfaf3e90c0c09ddf3 195652 libp11-kit-dev_0.23.15-2+deb10u1_armhf.deb 4581cff8d73acf4f4d1b94ce739a86b43d4da41d2c7b2b865312c4a73f841c09 1224940 libp11-kit0-dbgsym_0.23.15-2+deb10u1_armhf.deb 60b33c5f8394690ed7079179f461330873285337e4b9c315216b66414130ff18 292300 libp11-kit0_0.23.15-2+deb10u1_armhf.deb ac0cc1863d6f7ce5bab69dc5fa2664e78badd75dbab8823fd8930e80cf68a6fe 297736 p11-kit-dbgsym_0.23.15-2+deb10u1_armhf.deb b8b1061082326fbf0d2bb6633232f70755aa3745fccd3d42ad91edc3c7982a8e 1366268 p11-kit-modules-dbgsym_0.23.15-2+deb10u1_armhf.deb feac41c9e6d9e2b000c63f7ba6320ee7dfda067b983144d393b3ad5d4aec0d33 192136 p11-kit-modules_0.23.15-2+deb10u1_armhf.deb 7dfcbbe4e7f574631b9e18f2650ce4fe074c1dfaf34c2a0ca736f78b98b62b96 8144 p11-kit_0.23.15-2+deb10u1_armhf-buildd.buildinfo b52c3a882c09907927ace1131265ff88a2f73e3621b4d20d6b2b2fc562a52ed8 256476 p11-kit_0.23.15-2+deb10u1_armhf.deb Files: 933b77b55a5a7fdf7253b6f0f47dd368 195652 libdevel optional libp11-kit-dev_0.23.15-2+deb10u1_armhf.deb 8bf51fd9f203f246c706b7e2c63431cd 1224940 debug optional libp11-kit0-dbgsym_0.23.15-2+deb10u1_armhf.deb ded811b08e8d93f6ce2a1d745913233a 292300 libs optional libp11-kit0_0.23.15-2+deb10u1_armhf.deb 4c858567af67728697682eb9cd9b85c8 297736 debug optional p11-kit-dbgsym_0.23.15-2+deb10u1_armhf.deb d4e8b8c99a740a6cb090567e248295bc 1366268 debug optional p11-kit-modules-dbgsym_0.23.15-2+deb10u1_armhf.deb c689eed3e4be252f12f04c8adb9ee99a 192136 misc optional p11-kit-modules_0.23.15-2+deb10u1_armhf.deb ee85ba1544d73811a153abca806b2ee9 8144 libs optional p11-kit_0.23.15-2+deb10u1_armhf-buildd.buildinfo 459733026cb44072eac945c6216f5bc2 256476 misc optional p11-kit_0.23.15-2+deb10u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEnoraRnqJuvIXzMGCcXKNQn3Yf2UFAl/rR5cACgkQcXKNQn3Y f2VXExAA1UgKTx49savdHK7+Z0R6EYKc4kyDGOI9JVTk9uyqEwmcP+UUV9izjHis tZnyaXNChf1Ek5azQrxbmefLrAeutckC9wmZ6KCJXRaqX+N/g18EGI61LedGBegP G6/ZDeL+d4hPtW9u2iZ197yn2UFtefJj8HKHQqQ83MHGHZTDSyRWXzj+DKzOJ7dW ZxIpRJQHpZ4fUYIrE3q24aoUZQmuE4fZ8y+fz3E/whIPYNsKn0lg71QNtyncBdv6 T9EaJKKGFllzrNQVTjq+NHqyJjn6rGi3tvHmaEEc7IoGjIvQookhNF/210a9VGcF myKZR1XEc7fORMpA3KwuPQe4Bf/qknteCl0zMREAzC82198xL+6+gRdtDswuRrAg J1KTT0YuLsSl8N/7xN7NrIe/z88Jl1kM4j73Qx8TGHNVt5TzcBzyQpp0oMTko6ue 2fXb0AiSzWSkkyloEzVPklUCqyL8Hp6iJ7QBmfKDJF6FoI72w6D/mNqYrlvgzXVE 2zbR8FFPl4jZixUl0nQle4XyhRgO2cqA1MM3l2Du/jyqdngZWFbBgqjU+HuYnsx8 BJUkxgCF1fVijP3ohjQiaqWfxFJUn5ouxFRiMGoFy/CM9ZELVGeI+3PRV5WMI2YY 1d/69MFPrFIpaceJsLSeYrOMTh5AkYkqskp5KmPHMTux0gV2Ofo= =AjPf -----END PGP SIGNATURE-----