Your message dated Sat, 26 Oct 2024 18:04:43 +0000
with message-id <[email protected]>
and subject line Bug#1086039: fixed in botan 2.19.5+dfsg-3
has caused the Debian Bug report #1086039,
regarding botan: CVE-2024-50383
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1086039: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1086039
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: botan
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for botan.

CVE-2024-50383[0]:
| Botan before 3.6.0, when certain GCC versions are used, has a
| compiler-induced secret-dependent operation in lib/utils/donna128.h
| in donna128 (used in Chacha-Poly1305 and x25519). An addition can be
| skipped if a carry is not set. This was observed for GCC 11.3.0 with
| -O2 on MIPS, and GCC on x86-i386. (Only 32-bit processors can be
| affected.)

https://github.com/randombit/botan/commit/53b0cfde580e86b03d0d27a488b6c134f662e957

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-50383
    https://www.cve.org/CVERecord?id=CVE-2024-50383

Please adjust the affected versions in the BTS as needed.

--- End Message ---
--- Begin Message ---
Source: botan
Source-Version: 2.19.5+dfsg-3
Done: Laszlo Boszormenyi (GCS) <[email protected]>

We believe that the bug you reported is fixed in the latest version of
botan, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Laszlo Boszormenyi (GCS) <[email protected]> (supplier of updated botan package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 26 Oct 2024 19:12:49 +0200
Source: botan
Architecture: source
Version: 2.19.5+dfsg-3
Distribution: unstable
Urgency: high
Maintainer: Laszlo Boszormenyi (GCS) <[email protected]>
Changed-By: Laszlo Boszormenyi (GCS) <[email protected]>
Closes: 1086039
Changes:
 botan (2.19.5+dfsg-3) unstable; urgency=high
 .
   * Backport CVE-2024-50383 security fix for add more value barriers to avoid
     compiler induced side channels (closes: #1086039).
Checksums-Sha1:
 9b1b97dd1ba9f7577ce78cdd6aee8467ce5e793e 2125 botan_2.19.5+dfsg-3.dsc
 a38274b89fba6ca1f9b9539c404f925102afff20 11592 
botan_2.19.5+dfsg-3.debian.tar.xz
Checksums-Sha256:
 b3de3d7cdbb436f3522dc087b3965b3f604d250666184ff7825d9e8913161485 2125 
botan_2.19.5+dfsg-3.dsc
 cd36414ea2b626115a5cea60531ecfbc62eb48a2c7c2b80992538519211bca76 11592 
botan_2.19.5+dfsg-3.debian.tar.xz
Files:
 efbce7d154b040a6ff87e7917e50677e 2125 libs optional botan_2.19.5+dfsg-3.dsc
 3cf0c904ef3e53d025f6ee6190b20d29 11592 libs optional 
botan_2.19.5+dfsg-3.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEfYh9yLp7u6e4NeO63OMQ54ZMyL8FAmcdKEIACgkQ3OMQ54ZM
yL/P7Q//XluXFIj+3JU6xQMyli7+nEjnGRPybEvzHwgtYtPqeZoBp0l9kWYJWtk1
K9OG1CmHP6hfGMdj11r27dj8o6MH56uUh4NUC513VCgdc8CDK9lERfwoh8bgyXqb
9RnSx2WF1fpWZQ762aarkXq57Uuv/bLbj1sStc8rmvFxdAlX8mtjM7z9jK0GB8Cj
iEyJScGDa5Is2PuxDbD21pf3EKwWQeDM/DGCyN9W8gwNMXdbvp/ZbQheNqWC5SNH
WO6fAvxva6XDfES7M/NGnyg5VnzgIaZuy4XyJGXLAxVvmELDlHOsHRp6V5a0mqtY
W0+lmE06gX+a16kfaKPWJlAFYj8yczZzrRBBoZOU3SOVlPupgd/3GExm1tDZq1XF
p8q99E58uY7zVugRSTwjCbKDPNFtM2+X5XbK3JAfh+LkQ5GIyHvbyX5R/RSlBIqq
2EOB4dWUtVcVOlTG9cOl/X7tC2j0p6+NJQRqp5Pv8y3MXkK0U/I9jtwe+zmZIigE
nfDyvtHCiCkL5dnQfcEVDZABhjT8077Idb8iI/Hadznj7+aoKv6bpqz5mdnBZLD3
lWsC+n4rxnIB3dBoslJ9uBD6QezSj6fZWNd0NaMMJO12f9VbbnJ76b7Ex83P+Aba
vDxnZhO1AWhVf7/s+kx0RFI3G1Szj4uopHagobJAEj53hQD6hY8=
=sGBD
-----END PGP SIGNATURE-----

Attachment: pgpTAGvWSh3y2.pgp
Description: PGP signature


--- End Message ---

Reply via email to