From nobody Tue Apr 16 06:44:29 2024 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4VJZJt1Bp0z5Hx56; Tue, 16 Apr 2024 06:44:30 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4VJZJt0dL1z4lRg; Tue, 16 Apr 2024 06:44:30 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1713249870; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=ADhtZk+Ht1n8A7SLbDnqt9sdbC05Apoc3NP/XrPrIWw=; b=hcbMeYu8BwGMPrxkM2Q6v9UirVrDE/ORDf+MUciPWwLuaySqWxVfFhRbjwD/RBFE97kmhk TfRhiGG2vSc1YzXPQpBnd8MS0M3/DrE+TY8XC5KJXG+dxOw50MNerMs0BIinWchDvYUoZi DApG5znWqy0eXyC+zx2cZOIGPVP7muKx+GvkwptiupYy0leQhHILK46qmwlI/bdtpNhj++ xmateWeXQ4W1MfSkH9JJoxif7zMgHvpU+BIkInn5hshmhzCkPUZ4wD/CSqEhXeyy9EuNiX 1DNe8LaXBixZJN3yZCt63qs/UVycjpbI3caSCcwIJThhpxIS9fAVNZLxpDVxsQ== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1713249870; a=rsa-sha256; cv=none; b=OhxSSnv6we9AjUyDyto88kcCHJGQIs0SdKgnzld4ZnKhogMhhWQf6SEoiLutbxWjxtD5GW qwnOulRUJ4x4MF4j1FEls7UcvYdYWO+8NZtqAKaRnfExh2sZDr+cVW3+2VX2lJhwXTNCQ8 Tsb0+cPD7DN7nvTazmx4bCO8APnZNpiBUt0BMlvVUOWTNfGrRiarmQvAZjReXQb0XKCEHY ME4en0t6Dj3h37JLKUobsmc0mq54RkgzZIc55gn2O/csCbBPknJGFjuvmWEd3JfPpnnt9u 0KSpkf0K4O6nuECRx2wSn3anSPryPKpytXWDoilnxuTmDF0etUuseel/EuwpXg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1713249870; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=ADhtZk+Ht1n8A7SLbDnqt9sdbC05Apoc3NP/XrPrIWw=; b=E2VAcK/GY8WHGrbzkLagWeliTVNKYB7PTELuhpjcYNyRtpORoSw8FmQmKexzXSPQp+BZbQ RfAsdvTHoKuP5YcVOp6NHglwbhOB80eWlhnNr2EApwx47OtBHX2n4TO128I0Z0mFgSwHXs Bk1BAOzU4xqa2pXJsbISSt91CK80TZ4h17bviOYOC+4NsGmDgO8s1YyxHjF/Z+m9pDvRBt v2ffr4anumQhMSpaasV8rgBiQV9ppecQ7zE90A+Qoe6sTz/k9m/phaWnlOQOQYzy9O5+8e frPZHFVW1G05wPub4IrbUecoKh97zxdGNObkkU9fF+9HLRcMBnsVk0YYvVhGnw== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4VJZJt06mhzYdx; Tue, 16 Apr 2024 06:44:30 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 43G6iTuI062799; Tue, 16 Apr 2024 06:44:29 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 43G6iTfQ062796; Tue, 16 Apr 2024 06:44:29 GMT (envelope-from git) Date: Tue, 16 Apr 2024 06:44:29 GMT Message-Id: <202404160644.43G6iTfQ062796@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-branches@FreeBSD.org From: Matthias Andree Subject: git: 81b2882b9151 - 2024Q2 - security/putty: SECURITY update to 0.81 List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-ports-all@freebsd.org Sender: owner-dev-commits-ports-all@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: mandree X-Git-Repository: ports X-Git-Refname: refs/heads/2024Q2 X-Git-Reftype: branch X-Git-Commit: 81b2882b915181cb7106f67cf5af7dba561521d9 Auto-Submitted: auto-generated The branch 2024Q2 has been updated by mandree: URL: https://cgit.FreeBSD.org/ports/commit/?id=81b2882b915181cb7106f67cf5af7dba561521d9 commit 81b2882b915181cb7106f67cf5af7dba561521d9 Author: Matthias Andree AuthorDate: 2024-04-16 06:27:16 +0000 Commit: Matthias Andree CommitDate: 2024-04-16 06:40:12 +0000 security/putty: SECURITY update to 0.81 This fixes a vulnerability where NIST P521 ecdsa-sha2-nistp521 (only!) keys can be recovered easily because signature generation in PuTTY used a biased random number generator. MFH: 2024Q2 Security: 080936ba-fbb7-11ee-abc8-6960f2492b1d Security: CVE-2024-31497 (cherry picked from commit f8f9196ec1aa3e62b7e89d1630f4a61711737ffa) --- security/putty/Makefile | 4 ++-- security/putty/distinfo | 6 +++--- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/security/putty/Makefile b/security/putty/Makefile index c08756431cd9..b2d31c2b8aa9 100644 --- a/security/putty/Makefile +++ b/security/putty/Makefile @@ -1,6 +1,6 @@ PORTNAME= putty -DISTVERSION= 0.80 -PORTREVISION= 1 +DISTVERSION= 0.81 +PORTREVISION= 0 #DISTVERSIONSUFFIX= .0c59d49 CATEGORIES= security MASTER_SITES= http://the.earth.li/~sgtatham/putty/${PORTVERSION}/ \ diff --git a/security/putty/distinfo b/security/putty/distinfo index 0d88cf3d994a..d802e3c0fcf6 100644 --- a/security/putty/distinfo +++ b/security/putty/distinfo @@ -1,3 +1,3 @@ -TIMESTAMP = 1703023112 -SHA256 (putty-0.80.tar.gz) = 2013c83a721b1753529e9090f7c3830e8fe4c80a070ccce764539badb3f67081 -SIZE (putty-0.80.tar.gz) = 2831433 +TIMESTAMP = 1713247208 +SHA256 (putty-0.81.tar.gz) = cb8b00a94f453494e345a3df281d7a3ed26bb0dd7e36264f145206f8857639fe +SIZE (putty-0.81.tar.gz) = 2844616