Format: 1.8 Date: Mon, 03 Jul 2017 08:00:00 -0400 Source: libgcrypt20 Binary: libgcrypt20-doc libgcrypt20-dev libgcrypt20 libgcrypt20-udeb libgcrypt11-dev libgcrypt-mingw-w64-dev Architecture: i386 Version: 1.7.6-1ubuntu0.1 Distribution: zesty Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: libgcrypt-mingw-w64-dev - LGPL Crypto library - Windows development libgcrypt11-dev - transitional libgcrypt11-dev package libgcrypt20 - LGPL Crypto library - runtime library libgcrypt20-dev - LGPL Crypto library - development files libgcrypt20-doc - LGPL Crypto library - documentation libgcrypt20-udeb - LGPL Crypto library - runtime library (udeb) Changes: libgcrypt20 (1.7.6-1ubuntu0.1) zesty-security; urgency=medium . * SECURITY UPDATE: full RSA key recovery via side-channel attack - debian/patches/CVE-2017-7526-1.patch: simplify loop in mpi/mpi-pow.c. - debian/patches/CVE-2017-7526-2.patch: use same computation for square and multiply in mpi/mpi-pow.c. - debian/patches/CVE-2017-7526-3.patch: add exponent blinding in cipher/rsa.c. - debian/patches/CVE-2017-7526-4.patch: add free to cipher/rsa.c. - debian/patches/CVE-2017-7526-5.patch: add free to cipher/rsa.c. - CVE-2017-7526 * SECURITY UPDATE: EdDSA key recovery via side-channel attack - debian/patches/CVE-2017-9526-1.patch: store EdDSA session key in secure memory in cipher/ecc-eddsa.c. - debian/patches/CVE-2017-9526-2.patch: fix SEGV and stat calculation src/secmem.c. - CVE-2017-9526 Checksums-Sha1: 4fd515763a4a76ce47fc9a05ef59d96bc24f0fd4 6660 libgcrypt11-dev_1.5.4-3+really1.7.6-1ubuntu0.1_i386.deb 662776e2f11a2a8efd3fa0ad23e1b09914dcb33e 565972 libgcrypt20-dbgsym_1.7.6-1ubuntu0.1_i386.ddeb 2409c4f35059051e8f9b401c64cc8990de50f687 26544 libgcrypt20-dev-dbgsym_1.7.6-1ubuntu0.1_i386.ddeb cbaa1c1dbfc0d3687e2363092b406d97486148ba 423388 libgcrypt20-dev_1.7.6-1ubuntu0.1_i386.deb e1e0f17b88e315b607d13c7ca3be981d7922e0ac 565930 libgcrypt20-udeb-dbgsym_1.7.6-1ubuntu0.1_i386.ddeb bcd496d11eedc02da0ada6542b3fa4fcd9e82d89 343224 libgcrypt20-udeb_1.7.6-1ubuntu0.1_i386.udeb c86cbcb73c48893557f6ef83e6b2492731709594 373300 libgcrypt20_1.7.6-1ubuntu0.1_i386.deb Checksums-Sha256: 5e2a0eb35894b5c2e7daf980f08ff0093423a0790bb54b32885a6c279a7fd8b3 6660 libgcrypt11-dev_1.5.4-3+really1.7.6-1ubuntu0.1_i386.deb c5adc7db7b403ad4cd9c2054267fa41ba21f56b7e66e516c1c8b6d49e93ec72c 565972 libgcrypt20-dbgsym_1.7.6-1ubuntu0.1_i386.ddeb 79c4b36bbce09ce4f7381d9d96bb29d085d2b07ec2cfcca71e5657eef908da0c 26544 libgcrypt20-dev-dbgsym_1.7.6-1ubuntu0.1_i386.ddeb 67f55ed179509934c65aafe3fc1d5df9bbf0255a7564a9ca7eedbac01257dc64 423388 libgcrypt20-dev_1.7.6-1ubuntu0.1_i386.deb 7bde2b75b12fbcbf9cd8c3f367eada19a9b565913655b5e5d657e41eec4f3e12 565930 libgcrypt20-udeb-dbgsym_1.7.6-1ubuntu0.1_i386.ddeb 9b2bce68e6d276867f5cb859b6e6dddfaad993253309b2a5fa0bbf3812c9cde4 343224 libgcrypt20-udeb_1.7.6-1ubuntu0.1_i386.udeb 6a693b9c4e9b0966ed0c6c12b535c0c12f62e22b000644dd8e977a0d181c4de0 373300 libgcrypt20_1.7.6-1ubuntu0.1_i386.deb Files: 7a90e9a79f20084a5091fbdbcdaca3b8 6660 oldlibs extra libgcrypt11-dev_1.5.4-3+really1.7.6-1ubuntu0.1_i386.deb ef01ee7187237f694f853402ea2b737b 565972 libs extra libgcrypt20-dbgsym_1.7.6-1ubuntu0.1_i386.ddeb 702e5ca2fe5f42ae3e8c588c6d1fe1aa 26544 libdevel extra libgcrypt20-dev-dbgsym_1.7.6-1ubuntu0.1_i386.ddeb 9be2ccd0cf5ad9af28249622390d2ad3 423388 libdevel optional libgcrypt20-dev_1.7.6-1ubuntu0.1_i386.deb 2f33e1acc378450e6c43466568590619 565930 debian-installer extra libgcrypt20-udeb-dbgsym_1.7.6-1ubuntu0.1_i386.ddeb 34d04bcbd3a3b002d69c33d58bcf310a 343224 debian-installer optional libgcrypt20-udeb_1.7.6-1ubuntu0.1_i386.udeb 117f6485dafb734d19aa024c4e793c28 373300 libs standard libgcrypt20_1.7.6-1ubuntu0.1_i386.deb Original-Maintainer: Debian GnuTLS Maintainers