nettle (2.7.1-1ubuntu0.2) trusty-security; urgency=medium * SECURITY UPDATE: RSA cache timing side-channel attack - debian/patches/CVE-2016-6489.patch: use mpz_powm_sec and check for invalid keys in dsa-sign.c, rsa-blind.c, rsa-pkcs1-sign-tr.c, rsa-pkcs1-sign.c, rsa-sign.c, rsa.c, testsuite/rsa-test.c, rsa-decrypt-tr.c, rsa-decrypt.c. - CVE-2016-6489 -- Marc Deslauriers <email address hidden> Fri, 03 Feb 2017 08:40:39 -0500

- libhogweed2: low level cryptographic library (public-key cryptos)
Nettle is a cryptographic library that is designed to fit easily in more or

less any context: In crypto toolkits for object-oriented languages (C++,

Python, Pike, ...), in applications like LSH or GNUPG, or even in kernel

space.

.

It tries to solve a problem of providing a common set of cryptographic

algorithms for higher-level applications by implementing a

context-independent set of cryptographic algorithms. In that light, Nettle

doesn't do any memory allocation or I/O, it simply provides the

cryptographic algorithms for the application to use in any environment and

in any way it needs.

.

This package contains the asymmetric cryptographic algorithms, which,

require the GNU multiple precision arithmetic library (libgmp) for

their large integer computations.

- libhogweed2-dbgsym: debug symbols for package libhogweed2
- libnettle4: low level cryptographic library (symmetric and one-way cryptos)
- libnettle4-dbgsym: debug symbols for package libnettle4
- nettle-bin: low level cryptographic library (binary tools)
- nettle-bin-dbgsym: debug symbols for package nettle-bin
- nettle-dbg: low level cryptographic library (debugging symbols)
- nettle-dev: low level cryptographic library (development files)
