Comment 15 for bug 1928780

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package opencryptoki - 3.15.1+dfsg-0ubuntu1.2

---------------
opencryptoki (3.15.1+dfsg-0ubuntu1.2) hirsute-security; urgency=medium

  * SECURITY UPDATE: Invalid curve attacks
    - d/p/lp1928780-Add-missing-return-codes.patch: Partial cherry-pick of
      master as a prerequisite for the following fix.
    - d/p/lp1928780-SOFT-Check-the-EC-Key-on-C_CreateObject-and-C_Derive.patch:
      Cherry-picked to add checks preventing Invalid Curve attacks (LP: #1928780)

 -- Simon Chopin <email address hidden> Thu, 29 Jul 2021 10:22:13 +0200