Hello community,

here is the log from the commit of package libgcrypt for openSUSE:Factory 
checked in at 2017-06-05 18:49:58
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/libgcrypt (Old)
 and      /work/SRC/openSUSE:Factory/.libgcrypt.new (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "libgcrypt"

Mon Jun  5 18:49:58 2017 rev:64 rq:501083 version:1.7.7

Changes:
--------
--- /work/SRC/openSUSE:Factory/libgcrypt/libgcrypt.changes      2017-01-25 
22:32:30.967272306 +0100
+++ /work/SRC/openSUSE:Factory/.libgcrypt.new/libgcrypt.changes 2017-06-05 
18:50:00.528036877 +0200
@@ -1,0 +2,16 @@
+Sun Jun  4 19:26:12 UTC 2017 - astie...@suse.com
+
+- libgcrypt 1.7.7:
+  * Fix possible timing attack on EdDSA session key (previously
+    patched, drop libgcrypt-secure-EdDSA-session-key.patch)
+  * Fix long standing bug in secure memory implementation which
+    could lead to a segv on free
+
+-------------------------------------------------------------------
+Fri Jun  2 10:05:18 UTC 2017 - pmonrealgonza...@suse.com
+
+- Added libgcrypt-secure-EdDSA-session-key.patch [bsc#1042326]
+  * Store the session key in secure memory to ensure that constant
+    time point operations are used in the MPI library.
+
+-------------------------------------------------------------------

Old:
----
  libgcrypt-1.7.6.tar.bz2
  libgcrypt-1.7.6.tar.bz2.sig

New:
----
  libgcrypt-1.7.7.tar.bz2
  libgcrypt-1.7.7.tar.bz2.sig

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ libgcrypt.spec ++++++
--- /var/tmp/diff_new_pack.oh46p9/_old  2017-06-05 18:50:01.975832803 +0200
+++ /var/tmp/diff_new_pack.oh46p9/_new  2017-06-05 18:50:01.999829420 +0200
@@ -21,7 +21,7 @@
 %define libsoname %{name}20
 %define cavs_dir %{_libexecdir}/%{name}/cavs
 Name:           libgcrypt
-Version:        1.7.6
+Version:        1.7.7
 Release:        0
 Summary:        The GNU Crypto Library
 License:        GPL-2.0+ and LGPL-2.1+ and GPL-3.0+

++++++ libgcrypt-1.7.6.tar.bz2 -> libgcrypt-1.7.7.tar.bz2 ++++++
++++ 10217 lines of diff (skipped)


Reply via email to