-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 16 Jul 2024 10:13:59 +0000 Source: putty Binary: pterm pterm-dbgsym putty putty-dbgsym putty-tools putty-tools-dbgsym Architecture: mips64el Version: 0.74-1+deb11u2 Distribution: bullseye Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-03) Changed-By: Bastien Roucariès Description: pterm - PuTTY terminal emulator putty - Telnet/SSH client for X putty-tools - command-line tools for SSH, SCP, and SFTP Changes: putty (0.74-1+deb11u2) bullseye; urgency=medium . * Non-maintainer upload. * Cherry-pick from upstream: - Refactor the ssh_hash vtable. - Add an extra HMAC constructor function. - Fix CVE-2024-31497: biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. In other words, an adversary may already have enough signature information to compromise a victim's private key, even if there is no further use of vulnerable PuTTY versions. Checksums-Sha1: 3159dbe8da8189262c906a369617e50ca068c32a 708592 pterm-dbgsym_0.74-1+deb11u2_mips64el.deb bd65cb77e11bdf6f6c85eefc0d6975c1d8d3b1eb 208544 pterm_0.74-1+deb11u2_mips64el.deb 44c71a01d2c497061c1a786af1960f293f37331b 2270988 putty-dbgsym_0.74-1+deb11u2_mips64el.deb 831a23bff8ee3594bc22878a416886ecde123a52 3922020 putty-tools-dbgsym_0.74-1+deb11u2_mips64el.deb 0b5df46c98e225b245a1f917ccadc9f7e9c348ce 423980 putty-tools_0.74-1+deb11u2_mips64el.deb c7a23ef5becf6025073febd44e792f80a7962055 15983 putty_0.74-1+deb11u2_mips64el-buildd.buildinfo 87458594f66e0d09bcea1a213eee3d07466a96a4 434748 putty_0.74-1+deb11u2_mips64el.deb Checksums-Sha256: fa2868864c5cbf93c036ffebbd84b6d3e2d378e80d87d6a26a58611fdbbf60d0 708592 pterm-dbgsym_0.74-1+deb11u2_mips64el.deb 4193cbe52f59fd584cbca4085321d9a8baf5527bce489dbf14830305499473a8 208544 pterm_0.74-1+deb11u2_mips64el.deb 3aacd8947e997b25e5b60870146f9f12d305bf9841d0245ae46a65496a9d275e 2270988 putty-dbgsym_0.74-1+deb11u2_mips64el.deb f08e966f204f2f746af204e39c9f221e7bcf86443d94e8030fb52d3c7c478433 3922020 putty-tools-dbgsym_0.74-1+deb11u2_mips64el.deb fbf22d8cc32266686047b081887b94ead4f59b5544e60ed8fa4fd1bbf14934f9 423980 putty-tools_0.74-1+deb11u2_mips64el.deb e425284de1144e94891e1022e7751d2bb015c7528e1972c1e3e47d87135874ad 15983 putty_0.74-1+deb11u2_mips64el-buildd.buildinfo 014dc607d18c4892f5f2a10fea45ca1ff310fc82c64e3277a304e98c0c0e610b 434748 putty_0.74-1+deb11u2_mips64el.deb Files: dc338fdd6d00cf0031a84f3139a7b635 708592 debug optional pterm-dbgsym_0.74-1+deb11u2_mips64el.deb 7ca715be4d9b7925963dd9b767dbc3e9 208544 x11 optional pterm_0.74-1+deb11u2_mips64el.deb 24333ed9d8d7e79b829c82d8eff0ede0 2270988 debug optional putty-dbgsym_0.74-1+deb11u2_mips64el.deb 4b7198c76c88aa62fc843881c708fb39 3922020 debug optional putty-tools-dbgsym_0.74-1+deb11u2_mips64el.deb d9a3c0118b5b683e4a8b6b0055363417 423980 net optional putty-tools_0.74-1+deb11u2_mips64el.deb d4ceef0bb961400def114033213caca5 15983 net optional putty_0.74-1+deb11u2_mips64el-buildd.buildinfo 762269dcb3f0ad2ec48970aee9798c2c 434748 net optional putty_0.74-1+deb11u2_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEunmvxaaGKuI+hxxClmZGXOM83t8FAma4qNUACgkQlmZGXOM8 3t+Zrw/+MD9JqJQVosumJBwJCPhjimtz9xyjiapkblvt5gsV0Huv8gfHsqIRofAd YBELduc/J4hViZ5Dl2O3FWvJczn+g+MNhf9roJQUAUCjh7sGAjMFxXRbqE9G2bNb 0IsA2swcKhHvVo/3DTTGj2FG8JC5rihtkVblzpDAgLqNImNMJXOv5cQIrG2UevBo q04RGxU0AvfUNH4ngOMyma+Bpq7mS7TTt1MEOD8NB7V/SECczlFAwh4e3vhgP9Wg 6YULg6v+oxa8B0nf9VTtQeSUANHCclHaosBiszkUdpPJ7h0SsprLzlriysYB3Fdc K85ZbzecQpfP+txFV/cu491Lys4S6gkK74Uu8TP9HY5o1cz7PWHDmkaKduiEkJC5 2czUSj2Ayf5vnTx3IeJ9CS7OWXBitGS2qhbbPc1KwYdHNK2NAt24KFQn3ITTjHZF xTk5ntGYXYcLUgMd7hyhHQLwJGEvB+rUXAWWglmV3Lg9SJqVrGfKrq6ck/mAl9Me gR6Kp26C72mpEDjX1xWu37xaGOTrVw48BGHGsSs+c2SsD+V5/g4rSKb9pc2dn+Ef pGJYp5BXeCG4p4nkX1ZQh+JOFWveLVk+ndLhGTredgm57z1kDn8mhof0aj5ApgKm dxm8wYIniEWq9C0RRJENSM2AUd16tYJdes5Uj8KKjp1fA6B2BC8= =35zZ -----END PGP SIGNATURE-----