[ubuntu/artful-proposed] libgcrypt20 1.7.8-2ubuntu1 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Thu Sep 14 14:06:15 UTC 2017


libgcrypt20 (1.7.8-2ubuntu1) artful; urgency=medium

  * SECURITY UPDATE: Curve25519 side-channel attack
    - debian/patches/CVE-2017-0379.patch: add input validation for X25519
      to cipher/ecc.c, mpi/ec.c, src/mpi.h.
    - CVE-2017-0379

Date: Thu, 14 Sep 2017 07:14:32 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/libgcrypt20/1.7.8-2ubuntu1
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 14 Sep 2017 07:14:32 -0400
Source: libgcrypt20
Binary: libgcrypt20-doc libgcrypt20-dev libgcrypt20 libgcrypt20-udeb libgcrypt11-dev libgcrypt-mingw-w64-dev
Architecture: source
Version: 1.7.8-2ubuntu1
Distribution: artful
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description:
 libgcrypt-mingw-w64-dev - LGPL Crypto library - Windows development
 libgcrypt11-dev - transitional libgcrypt11-dev package
 libgcrypt20 - LGPL Crypto library - runtime library
 libgcrypt20-dev - LGPL Crypto library - development files
 libgcrypt20-doc - LGPL Crypto library - documentation
 libgcrypt20-udeb - LGPL Crypto library - runtime library (udeb)
Changes:
 libgcrypt20 (1.7.8-2ubuntu1) artful; urgency=medium
 .
   * SECURITY UPDATE: Curve25519 side-channel attack
     - debian/patches/CVE-2017-0379.patch: add input validation for X25519
       to cipher/ecc.c, mpi/ec.c, src/mpi.h.
     - CVE-2017-0379
Checksums-Sha1:
 1c13689e22fdc63bd73362a8419c0bbe2743da2a 3007 libgcrypt20_1.7.8-2ubuntu1.dsc
 e556846f5206fc78ab02686a8c614de461dcda85 28436 libgcrypt20_1.7.8-2ubuntu1.debian.tar.xz
 e5947153f8ceba2ec0795a05dd2e4b69025019b8 5743 libgcrypt20_1.7.8-2ubuntu1_source.buildinfo
Checksums-Sha256:
 dfd3aa72d725333a8bbfd60232e50971e90f7b327a043aceb7bbf8b721df6745 3007 libgcrypt20_1.7.8-2ubuntu1.dsc
 e9f1b95a1024ee378198b96e5d04e43b4705214e5cb6ec8f553f765f7212f356 28436 libgcrypt20_1.7.8-2ubuntu1.debian.tar.xz
 7592f4ac724aa803835f7e14f1663c5da2340cebbc621a8fda35852a25615065 5743 libgcrypt20_1.7.8-2ubuntu1_source.buildinfo
Files:
 00613550325e21308f6a0fa4956e523f 3007 libs optional libgcrypt20_1.7.8-2ubuntu1.dsc
 9172ecb01fd07080818e38e2ae35c416 28436 libs optional libgcrypt20_1.7.8-2ubuntu1.debian.tar.xz
 fdf834db30ff2c556f3fe83396bfc6e5 5743 libs optional libgcrypt20_1.7.8-2ubuntu1_source.buildinfo
Original-Maintainer: Debian GnuTLS Maintainers <pkg-gnutls-maint at lists.alioth.debian.org>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJZuowaAAoJEGVp2FWnRL6T1MUP/1w9EgyNiCWWDWll9lS9cQBy
b2g2OnpmkIArlfudv34IiN7aZJyknPLS9QX1rWxQZtPPoHB5pR0gOqOSYPqen15U
CZDUxJ4ysaeJApSM+rcvMrw3bqmW41Xh29bYpTnOs9xYQdQ5GO49bluj4l5eShd/
RrsRBEm8bXt4Nec86l+rp8TPfy5IcG5XZWa25YAslTo64fPwEc6yfdDJt/cNMgxy
43t137IVmH0mTqmt0PhR5VeCdNcoV/Jp0zAcS3y7iD+mUr18v2tls34K0k4I0sMa
WFWKmuPzVSLONeX5paOwa7r7WKswmERU/lQSvvidmCMdSa4PsGU9SwOBPCgdipyg
4zK0CxMWZDX5GySgBoY33WKgsKWUEwUVAmC3mtYIEor/cgEWWSAezLBM565aNE5o
8x/1UmahRdstdtv2vpjuPFS1/OljVarOj9AXMs/4w/V+rfhnQp62/qWDbLFYj/dH
J5NlfSHexKEmzKCVGYYq4s89nL5YRE2Njzx77/lbdOe1go9ItiZjWfNhF51XSE4/
Kf0lXCssINcKfJTtyN6mgyghlPLUiMZZJUKVbVrAEgYzu5Cz2p69fSLgLHyWAXlh
RRzBNFnYwjdQqNCYmwySMuFn2RjEI/+WQVww92EAk+6L51LVbR3tCFwfXkREx1/4
rc3LxP8Tgg1Hw8S7nriW
=l8dF
-----END PGP SIGNATURE-----


More information about the Artful-changes mailing list