Your message dated Thu, 21 Dec 2023 21:06:35 +0000
with message-id <[email protected]>
and subject line Bug#1056188: fixed in gnutls28 3.7.1-5+deb11u4
has caused the Debian Bug report #1056188,
regarding gnutls28: CVE-2023-5981: timing side-channel inside RSA-PSK key 
exchange
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1056188: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1056188
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: gnutls28
Version: 3.8.1-4
Severity: important
Tags: security upstream
Forwarded: https://gitlab.com/gnutls/gnutls/-/issues/1511
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

[Andreas, just filling for having a BTS reference, realize you know
already]

The following vulnerability was published for gnutls28.

CVE-2023-5981[0]:
| timing side-channel inside RSA-PSK key exchange


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-5981
    https://www.cve.org/CVERecord?id=CVE-2023-5981
[1] https://gitlab.com/gnutls/gnutls/-/issues/1511
[2] https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23
[3] 
https://gitlab.com/gnutls/gnutls/-/commit/29d6298d0b04cfff970b993915db71ba3f580b6d

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: gnutls28
Source-Version: 3.7.1-5+deb11u4
Done: Andreas Metzler <[email protected]>

We believe that the bug you reported is fixed in the latest version of
gnutls28, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Andreas Metzler <[email protected]> (supplier of updated gnutls28 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 30 Nov 2023 11:37:44 +0100
Source: gnutls28
Architecture: source
Version: 3.7.1-5+deb11u4
Distribution: bullseye
Urgency: medium
Maintainer: Debian GnuTLS Maintainers <[email protected]>
Changed-By: Andreas Metzler <[email protected]>
Closes: 1056188
Changes:
 gnutls28 (3.7.1-5+deb11u4) bullseye; urgency=medium
 .
   * Backport fix for CVE-2023-5981 / GNUTLS-SA-2023-10-23 (timing sidechannel
     in RSA-PSK key exchange) from 3.8.2. Closes: #1056188
Checksums-Sha1: 
 bf6eb59f897d9347ff347dabb50bfd40c708b7af 3519 gnutls28_3.7.1-5+deb11u4.dsc
 35a849384718a63433565abf42f6628bc8d78578 97368 
gnutls28_3.7.1-5+deb11u4.debian.tar.xz
Checksums-Sha256: 
 fe12190b21d411f2028df335af346a0065e802ab9093c79edcaf7244d644c383 3519 
gnutls28_3.7.1-5+deb11u4.dsc
 b9e12496d76db8f1fd95aa9467a7ef680e74fe0be1314e138aba83c737780d61 97368 
gnutls28_3.7.1-5+deb11u4.debian.tar.xz
Files: 
 5e6c18a695ffc095af8eee06cbd73c86 3519 libs optional 
gnutls28_3.7.1-5+deb11u4.dsc
 9f9130d79c2fd4d4590a4fb842c0a53d 97368 libs optional 
gnutls28_3.7.1-5+deb11u4.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE0uCSA5741Jbt9PpepU8BhUOCFIQFAmVodUMACgkQpU8BhUOC
FIQSPA//ccgQpYZjGipmD5QxOPOB7RnJJTyKw2cNbo8Yqa2RSRfzwnfIhuexJQCL
+YmlhHC78mWNFv83buN6+PlWDNgM3ASVQgKD6tCTcEllWwHNpJjCPz9ux5kKUdOV
mdXeGCmZt1Xvi5BBdBs6qY9Iqzh1XHFvWkPadlGRgpSszyGx0ay6xY/NU4SYVBkO
mUm80mmLJjnmoQ9ejC041dlR6yjGkwwuJeJD38eoyPlNT7QY9e3XQsOt8HtwK+92
b3lwzLLs71AKvpP6oPsnStX4CA7cFlho0fFHQs4ELZg6SVdOPdK6SpWGMBxZH3JC
i+8cSojTrd3hU2ivaSnmhOu/Vb9E08CthOUhdKNcNbpLvkyCLFzFqB9fuhG/Mn2N
Qmbvw0Aq6OcB1ArVPndZNV8X7LOMMc0yueit/CDWNKOK8/GJxG12VijojpcLUQLc
jq3OfOIgUNR37938ncFzrWtpCIrITPEsXGZlT41mJiP+N4NwpKIeZDw/VDeqN9t1
wp+TFGoKq1H0EPE6nURsDsDNp+FsuRBy6mlF7Smz6crHtXzHYkYS9ivl44xoogk1
i3Z5XShLuUKXs0L4zgEVoxZD7I8jIGutQ8SGL0qlcBX5DXHnXxL+BwWQPKYSod2G
kPncq6exDQXfh9z+LBm6nMExFyZDoABuIxEdD4FA7BQ1KwZ019c=
=+qUS
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to