libgcrypt11 (1.5.0-3ubuntu0.9) precise-security; urgency=medium
[ Marc Deslauriers ]
* SECURITY UPDATE: ECDSA timing attack
- debian/patches/CVE-2019-13627.patch: add mitigation against timing
attack in cipher/ecc.c, mpi/ec.c.
- CVE-2019-13627
libgcrypt11 (1.5.0-3ubuntu0.8) precise-security; urgency=medium
* SECURITY UPDATE: memory-cache side-channel attack on ECDSA signatures
- debian/patches/CVE-2018-0495.patch: add blinding for ECDSA in
cipher/ecc.
- CVE-2018-0495
libgcrypt11 (1.5.0-3ubuntu0.7) precise-security; urgency=medium
* SECURITY UPDATE: full RSA key recovery via side-channel attack
- debian/patches/CVE-2017-7526-1.patch: simplify loop in mpi/mpi-pow.c.
- debian/patches/CVE-2017-7526-2.patch: use same computation for square
and multiply in mpi/mpi-pow.c.
- debian/patches/CVE-2017-7526-3.patch: add exponent blinding in
cipher/rsa.c.
- debian/patches/CVE-2017-7526-4.patch: add free to cipher/rsa.c.
- debian/patches/CVE-2017-7526-5.patch: add free to cipher/rsa.c.
- CVE-2017-7526
Date: 2020-01-28 15:47:24.609573+00:00
Changed-By: leo.barb...@canonical.com (Leonidas S. Barbosa)
Signed-By: Ubuntu Archive Robot <ubuntu-archive-ro...@lists.canonical.com>
https://launchpad.net/ubuntu/+source/libgcrypt11/1.5.0-3ubuntu0.9
Sorry, changesfile not available.
--
Precise-changes mailing list
Precise-changes@lists.ubuntu.com
Modify settings or unsubscribe at:
https://lists.ubuntu.com/mailman/listinfo/precise-changes