-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 10 Feb 2025 10:07:24 +0100 Source: gnutls28 Architecture: source Version: 3.7.9-2+deb12u4 Distribution: bookworm-security Urgency: medium Maintainer: Debian GnuTLS Maintainers Changed-By: Andreas Metzler Changes: gnutls28 (3.7.9-2+deb12u4) bookworm-security; urgency=medium . * libgnutls: Fix potential DoS in handling certificates with numerous name constraints, as a follow-up of CVE-2024-12133 in libtasn1. Patch cherry-picked from 3.8.9 release. [GNUTLS-SA-2025-02-07, CVSS: medium] [CVE-2024-12243] Checksums-Sha1: c6f666250dfee97d09c6f94bae571bc0d8afaa2a 3421 gnutls28_3.7.9-2+deb12u4.dsc 8896a303b70481dbfa6e3824a0d62ccd36acad29 6377212 gnutls28_3.7.9.orig.tar.xz 916229852eefcd91143e657e0ff35936b86aa769 996 gnutls28_3.7.9.orig.tar.xz.asc c04ddcaabe0934a2fab61f81c4078e15eab2255f 110608 gnutls28_3.7.9-2+deb12u4.debian.tar.xz 61b90e7a40ae0b9bb1c161448a3bbe9a7cd1c44b 7507 gnutls28_3.7.9-2+deb12u4_source.buildinfo Checksums-Sha256: 2b0d6945d682aa97561b4cb5ffe8ba202074fe4d35fc0e6d34adec2131dcb870 3421 gnutls28_3.7.9-2+deb12u4.dsc aaa03416cdbd54eb155187b359e3ec3ed52ec73df4df35a0edd49429ff64d844 6377212 gnutls28_3.7.9.orig.tar.xz da4a96b14edd3cd44971a36ba1e976af1057e57a2d6c21b0cc7025c983ee84cc 996 gnutls28_3.7.9.orig.tar.xz.asc 40cf28142e9fe9cba6c62c99bce3ccfa33f838faa7ba8c7f3aed62b04c751c1f 110608 gnutls28_3.7.9-2+deb12u4.debian.tar.xz d8f6b756771d9d51193b67ad6e2c0d21d34213350cb99b4e104b68279fa62536 7507 gnutls28_3.7.9-2+deb12u4_source.buildinfo Files: abdf7fe84855a7d5af85d30925d1f5a4 3421 libs optional gnutls28_3.7.9-2+deb12u4.dsc 191b8bac4c8aac468549ca64ac2f30b6 6377212 libs optional gnutls28_3.7.9.orig.tar.xz e2d4b76bae625c6daafc2582b112df82 996 libs optional gnutls28_3.7.9.orig.tar.xz.asc 4e324bb51399acc69f3f6787eb93a91a 110608 libs optional gnutls28_3.7.9-2+deb12u4.debian.tar.xz 59611cf14ed08dbf2bdef0e8661b5e7f 7507 libs optional gnutls28_3.7.9-2+deb12u4_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0uCSA5741Jbt9PpepU8BhUOCFIQFAmes/SAACgkQpU8BhUOC FIS7hQ/9FYvwR5p3K/1+jAjdxyAgL6OzGsY3QKgxdsfDxugsukJeBVBEFR3Kwzfo s1gG8MLkNDFGyyTFr6cdKNm2pCvwg2IMLP2sFch4UJB7UAVd2jOixvS54ikFkFD9 fDuw+AE3L9MkdyqQSkPPDRwsziSsl/Dm5PVO9xTgA7OD2YyQUfEgJC9h9tSKH/7z mQ1FD/xG9zCVkLNGdV1WmuQ7itjPMNcf6OUYnFmDe/H8Xvy9R72nrwG27laNkvEk ZoncEHc4eP78N4J7jH32W01mOoFNGTMzlJdowi8pH5SdpxnIjOeweppGmoxMC8Qf b1r1HnfrXrDHKOfjelpLZbKsNjwomGVScvBa3tuJP9QepWj9jEjV+UsZnqe/UoXX SFi8i28z0p1GuwtZyKhSPIFFBG+haR818LfZQtU99Ck3UAtYQvrV1SwVJwZF/Sgs 1srEdFBX2leR60uobmfNh5aoCLYZojqyaM92i6AEgA0z9hyRFVK4RwKVWCEMVSgP 95RZMn0+nhklXI07yXqPvwofHkyT4HNv98iLkwJ4tXsUeXCfLCh7nf/TJXBFd0Uh 8l0405xe6vbYCBtkaDjFjbg2C2zbCYWA90qtsRkesHFuDuqHl5sCJlN1v/vTlYCu jvWu9caDczCaI295AL8pQ33399jXxWK/INKVjQq+E7m2LEVsi40= =lXts -----END PGP SIGNATURE-----