libgcrypt20 1.7.2-2ubuntu1.1 source package in Ubuntu

Changelog

libgcrypt20 (1.7.2-2ubuntu1.1) yakkety-security; urgency=medium

  * SECURITY UPDATE: full RSA key recovery via side-channel attack
    - debian/patches/CVE-2017-7526-1.patch: simplify loop in mpi/mpi-pow.c.
    - debian/patches/CVE-2017-7526-2.patch: use same computation for square
      and multiply in mpi/mpi-pow.c.
    - debian/patches/CVE-2017-7526-3.patch: add exponent blinding in
      cipher/rsa.c.
    - debian/patches/CVE-2017-7526-4.patch: add free to cipher/rsa.c.
    - debian/patches/CVE-2017-7526-5.patch: add free to cipher/rsa.c.
    - CVE-2017-7526
  * SECURITY UPDATE: EdDSA key recovery via side-channel attack
    - debian/patches/CVE-2017-9526-1.patch: store EdDSA session key in
      secure memory in cipher/ecc-eddsa.c.
    - debian/patches/CVE-2017-9526-2.patch: fix SEGV and stat calculation
      src/secmem.c.
    - CVE-2017-9526

 -- Marc Deslauriers <email address hidden>  Mon, 03 Jul 2017 08:15:20 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Yakkety
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
libs
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
libgcrypt20_1.7.2.orig.tar.bz2 2.7 MiB 3d35df906d6eab354504c05d749a9b021944cb29ff5f65c8ef9c3dd5f7b6689f
libgcrypt20_1.7.2-2ubuntu1.1.debian.tar.xz 36.1 KiB 6d2b3d89c05248060f0ee7cdec24a0f65f6dc9dac34113969af4e2c9ea28bab0
libgcrypt20_1.7.2-2ubuntu1.1.dsc 2.7 KiB c92b6f4635ff74709e344702a3980fae862240bd8e4b25f4f085925b9f27af75

View changes file

Binary packages built by this source

libgcrypt-mingw-w64-dev: No summary available for libgcrypt-mingw-w64-dev in ubuntu yakkety.

No description available for libgcrypt-mingw-w64-dev in ubuntu yakkety.

libgcrypt11-dev: No summary available for libgcrypt11-dev in ubuntu yakkety.

No description available for libgcrypt11-dev in ubuntu yakkety.

libgcrypt20: No summary available for libgcrypt20 in ubuntu yakkety.

No description available for libgcrypt20 in ubuntu yakkety.

libgcrypt20-dbgsym: No summary available for libgcrypt20-dbgsym in ubuntu yakkety.

No description available for libgcrypt20-dbgsym in ubuntu yakkety.

libgcrypt20-dev: No summary available for libgcrypt20-dev in ubuntu yakkety.

No description available for libgcrypt20-dev in ubuntu yakkety.

libgcrypt20-dev-dbgsym: No summary available for libgcrypt20-dev-dbgsym in ubuntu yakkety.

No description available for libgcrypt20-dev-dbgsym in ubuntu yakkety.

libgcrypt20-doc: No summary available for libgcrypt20-doc in ubuntu yakkety.

No description available for libgcrypt20-doc in ubuntu yakkety.

libgcrypt20-udeb: No summary available for libgcrypt20-udeb in ubuntu yakkety.

No description available for libgcrypt20-udeb in ubuntu yakkety.

libgcrypt20-udeb-dbgsym: No summary available for libgcrypt20-udeb-dbgsym in ubuntu yakkety.

No description available for libgcrypt20-udeb-dbgsym in ubuntu yakkety.