Bug#864083: unblock: libgcrypt20/1.7.6-2

Andreas Metzler ametzler at bebt.de
Sun Jun 4 08:30:44 UTC 2017

Package: release.debian.org
Severity: normal
User: release.debian.org at packages.debian.org
Usertags: unblock

Please unblock package libgcrypt20, the upload features the following
* Refresh debian/upstream/signing-key.asc, key-expiry-dates bumped.
* Pull two fixes from gcrypt 1.7.7 bugfix release:
  + 30_gcry177_01-ecc-Store-EdDSA-session-key-in-secure-memory.patch
    Fix possible timing attack on EdDSA session key.
  + 30_gcry177_02-secmem-Fix-SEGV-and-stat-calculation.patch
    Fix long standing bug in secure memory implementation which could lead
    to a segv on free.

unblock libgcrypt20/1.7.6-2

Thanks, cu Andreas
`What a good friend you are to him, Dr. Maturin. His other friends are
so grateful to you.'
`I sew his ears on from time to time, sure'
-------------- next part --------------
A non-text attachment was scrubbed...
Name: from_1.7.6-1_to_-2.diff
Type: text/x-diff
Size: 19278 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/pkg-gnutls-maint/attachments/20170604/963b3c93/attachment.diff>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/pkg-gnutls-maint/attachments/20170604/963b3c93/attachment.sig>

More information about the Pkg-gnutls-maint mailing list