-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 29 Dec 2020 15:48:30 +0100 Source: p11-kit Binary: libp11-kit-dev libp11-kit0 libp11-kit0-dbgsym p11-kit p11-kit-dbgsym p11-kit-modules p11-kit-modules-dbgsym Architecture: i386 Version: 0.23.15-2+deb10u1 Distribution: buster-security Urgency: high Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Salvatore Bonaccorso Description: libp11-kit-dev - library for loading and coordinating access to PKCS#11 modules - libp11-kit0 - library for loading and coordinating access to PKCS#11 modules - p11-kit - p11-glue utilities p11-kit-modules - p11-glue proxy and trust modules Changes: p11-kit (0.23.15-2+deb10u1) buster-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix bounds check in p11_rpc_buffer_get_byte_array (CVE-2020-29362) * Check attribute length against buffer size (CVE-2020-29363) * Check for arithmetic overflows before allocating (CVE-2020-29361) * Follow-up to arithmetic overflow fix (CVE-2020-29361) Checksums-Sha1: f7135f52a3aa1f6ae2048c376499a5490f4e7bcf 195672 libp11-kit-dev_0.23.15-2+deb10u1_i386.deb a1eb3a03751995ab07fcd4a7782aa9c10f89adf4 859460 libp11-kit0-dbgsym_0.23.15-2+deb10u1_i386.deb 52eaa636dab04baba44f8d6d4b4aebd61cc9ea75 309944 libp11-kit0_0.23.15-2+deb10u1_i386.deb f0dcdcb7b8b1db725b7143b0718b6da1125cfe94 268104 p11-kit-dbgsym_0.23.15-2+deb10u1_i386.deb 0f3ca5b9578040437a3b78edc364455b42498834 976980 p11-kit-modules-dbgsym_0.23.15-2+deb10u1_i386.deb f2c6427e1f9170578a74d747e4503902a177b60c 221244 p11-kit-modules_0.23.15-2+deb10u1_i386.deb 909dcb7a00f159c58f7bcce5712e67ede5291299 8197 p11-kit_0.23.15-2+deb10u1_i386.buildinfo 488d5f036191f652d805dbd6629602e9f6d9db8d 271364 p11-kit_0.23.15-2+deb10u1_i386.deb Checksums-Sha256: 7666890cdb8330f1a6e97c2fc35cdece01e9df77389d9a5b5abd4c496b803e7a 195672 libp11-kit-dev_0.23.15-2+deb10u1_i386.deb a427332f5276372dccf4088ab601710be05906734dbcb1266bf08f3e3022ba97 859460 libp11-kit0-dbgsym_0.23.15-2+deb10u1_i386.deb 5f250da8f0091a93fe13fd38763e999fac66000acf87fa625ee968abd934c4c9 309944 libp11-kit0_0.23.15-2+deb10u1_i386.deb adaaaa225e5aad109299ff097befa0ae1ea4443054bfa04454d5f796ba0e9d27 268104 p11-kit-dbgsym_0.23.15-2+deb10u1_i386.deb 6b048b2ae1098f12c73cecc0b890f8ed6c7790f654e63b2080b15f869af1024b 976980 p11-kit-modules-dbgsym_0.23.15-2+deb10u1_i386.deb ba77acba4995ea8d211ba2aca6b6de73b380c5a291d035222408888e6d66d54c 221244 p11-kit-modules_0.23.15-2+deb10u1_i386.deb d4650280b56b3009d0bbeea2d9958103ac2e60605172c81089723ce699ec2a6f 8197 p11-kit_0.23.15-2+deb10u1_i386.buildinfo 79b1e0f286df6a39d3ad62d1dc655bb5d8ba2fbd1d45ccc7b7f75f54858f44cf 271364 p11-kit_0.23.15-2+deb10u1_i386.deb Files: f4c85b8b27bff06a5e642bc317939328 195672 libdevel optional libp11-kit-dev_0.23.15-2+deb10u1_i386.deb 9df4288128c0a7feda9450adde11e68c 859460 debug optional libp11-kit0-dbgsym_0.23.15-2+deb10u1_i386.deb 0b202dcb2390d0436f0cb03c8a013f20 309944 libs optional libp11-kit0_0.23.15-2+deb10u1_i386.deb 78c21aa24b400e090e993aef71785e04 268104 debug optional p11-kit-dbgsym_0.23.15-2+deb10u1_i386.deb 2a150d49c82b48b5b2938e08927a2c83 976980 debug optional p11-kit-modules-dbgsym_0.23.15-2+deb10u1_i386.deb 765160854bbd80e57f23f7c0185e9f5b 221244 misc optional p11-kit-modules_0.23.15-2+deb10u1_i386.deb 8c01c96141b7722fcbb3bae5def9b353 8197 libs optional p11-kit_0.23.15-2+deb10u1_i386.buildinfo 919caad76ee6adf84c872a526885afae 271364 misc optional p11-kit_0.23.15-2+deb10u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEeShLnnjT5e2dm1q4H4Xht4aLclgFAl/rRy4ACgkQH4Xht4aL clgtABAAhlkh8YjOnANuS6Dt43BM0PqrT7QEFeSSyp9s2YQlR5rOC33BslCreEZK 6axsUKMXfl9XJn2fQWrGlbn5579otg972DER+4tvPShmmchPYxuPvFN9huqcqQ6S j82nbSGeKwUCVVsgk30xMDsuHwAl8n3RoczIGqN5+WS8kYDjxvVmxWWef2MgU2+y BMwVW5oqW3TD53TiN69Ca56sr1A4j35KSbGAfDeJhrNyhHbuNbw+++f5h0YcUgs2 z+rG0aR9rq50Ybf5216LA7imh4x7nwbiCZrnPOPtA0LbMykuADeijbkxE79jgkmY uhsnQFEUSWADZ2Goo0yus7Am91JUqPDGa1OuGSPbIndtIefbjl7/nAo1HAt1ylcx eFWkJAb8s/fFq4KlUP6vlhPqzMwVDoHZhQWXFk1qhgS9KpoCHbGeQe3x0V/gHCG1 5vWduudeLjqt9UeqmowD5oIpBczZKQERqNeTtnLCaWqLtMG6tXvPgJ8URLBRnENU A5SeQHJnFxgOCd56AvgcEzaQ7zK8zWCmq4xW4J3amLBkrjDKPMUxBAQyVkBreYiO VyLf/yD/Aytpw5O2vvsep32llu4IwFrGgB7lGTcoC7anUoZ8pukwiOOXd1z7WI9p X7EWmnOPH/GVUnjQ6ZGCw+0NWfSvhI64Ix79SD5MfQM3z+D/Qeo= =Q18J -----END PGP SIGNATURE-----