libgcrypt20 1.7.6-1ubuntu0.1 source package in Ubuntu

Changelog

libgcrypt20 (1.7.6-1ubuntu0.1) zesty-security; urgency=medium

  * SECURITY UPDATE: full RSA key recovery via side-channel attack
    - debian/patches/CVE-2017-7526-1.patch: simplify loop in mpi/mpi-pow.c.
    - debian/patches/CVE-2017-7526-2.patch: use same computation for square
      and multiply in mpi/mpi-pow.c.
    - debian/patches/CVE-2017-7526-3.patch: add exponent blinding in
      cipher/rsa.c.
    - debian/patches/CVE-2017-7526-4.patch: add free to cipher/rsa.c.
    - debian/patches/CVE-2017-7526-5.patch: add free to cipher/rsa.c.
    - CVE-2017-7526
  * SECURITY UPDATE: EdDSA key recovery via side-channel attack
    - debian/patches/CVE-2017-9526-1.patch: store EdDSA session key in
      secure memory in cipher/ecc-eddsa.c.
    - debian/patches/CVE-2017-9526-2.patch: fix SEGV and stat calculation
      src/secmem.c.
    - CVE-2017-9526

 -- Marc Deslauriers <email address hidden>  Mon, 03 Jul 2017 08:00:00 -0400

Upload details

Uploaded by:
Marc Deslauriers on 2017-07-03
Uploaded to:
Zesty
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
libs
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
libgcrypt20_1.7.6.orig.tar.bz2 2.8 MiB 626aafee84af9d2ce253d2c143dc1c0902dda045780cc241f39970fc60be05bc
libgcrypt20_1.7.6.orig.tar.bz2.asc 310 bytes 91ad5a0efafb0edc63c083f733ce476b2a0da663aea5118126aa63825d314e00
libgcrypt20_1.7.6-1ubuntu0.1.debian.tar.xz 34.3 KiB 93ba6df55eae0a8687a7c381141caae4430e23df98a7e3d9450a9b137623b03a
libgcrypt20_1.7.6-1ubuntu0.1.dsc 2.9 KiB 17e75d3d71ff654209263e249d407e7076fdac6b3907f5f06757220438ab85b9

View changes file

Binary packages built by this source

libgcrypt-mingw-w64-dev: No summary available for libgcrypt-mingw-w64-dev in ubuntu zesty.

No description available for libgcrypt-mingw-w64-dev in ubuntu zesty.

libgcrypt11-dev: No summary available for libgcrypt11-dev in ubuntu zesty.

No description available for libgcrypt11-dev in ubuntu zesty.

libgcrypt20: No summary available for libgcrypt20 in ubuntu zesty.

No description available for libgcrypt20 in ubuntu zesty.

libgcrypt20-dbgsym: No summary available for libgcrypt20-dbgsym in ubuntu zesty.

No description available for libgcrypt20-dbgsym in ubuntu zesty.

libgcrypt20-dev: No summary available for libgcrypt20-dev in ubuntu zesty.

No description available for libgcrypt20-dev in ubuntu zesty.

libgcrypt20-dev-dbgsym: No summary available for libgcrypt20-dev-dbgsym in ubuntu zesty.

No description available for libgcrypt20-dev-dbgsym in ubuntu zesty.

libgcrypt20-doc: No summary available for libgcrypt20-doc in ubuntu zesty.

No description available for libgcrypt20-doc in ubuntu zesty.

libgcrypt20-udeb: No summary available for libgcrypt20-udeb in ubuntu zesty.

No description available for libgcrypt20-udeb in ubuntu zesty.

libgcrypt20-udeb-dbgsym: No summary available for libgcrypt20-udeb-dbgsym in ubuntu zesty.

No description available for libgcrypt20-udeb-dbgsym in ubuntu zesty.