Publishing details

Changelog

libgcrypt20 (1.6.2-4ubuntu2.1) vivid-security; urgency=medium

  * SECURITY UPDATE: side-channel attack on ECDH
    - debian/patches/CVE-2015-7511.patch: perform input validation and fix
      error paths in cipher/ecc.c, use constant-time multiplication in
      mpi/ec.c.
    - CVE-2015-7511
  * SECURITY UPDATE: random number generator prediction
    - debian/patches/CVE-2016-6313-1.patch: improve the diagram showing the
      random mixing in random/random-csprng.c.
    - debian/patches/CVE-2016-6313-2.patch: hash continuous areas in the
      csprng pool in random/random-csprng.c.
    - CVE-2016-6313
  * debian/rules: disable unaligned memory access on arm to fix FTBFS.

 -- Emily Ratliff <email address hidden>  Mon, 30 Jan 2017 21:56:29 -0600

Available diffs

Builds

Built packages

Package files