UbuntuUpdates.org

Package "libgcrypt20"

Name: libgcrypt20

Description:

LGPL Crypto library - runtime library

Latest version: 1.6.1-2ubuntu1.14.04.1
Release: trusty (14.04)
Level: security
Repository: universe
Homepage: http://directory.fsf.org/project/libgcrypt/

Links

Save this URL for the latest version of "libgcrypt20": https://www.ubuntuupdates.org/libgcrypt20


Download "libgcrypt20"


Other versions of "libgcrypt20" in Trusty

Repository Area Version
base universe 1.6.1-2ubuntu1
updates universe 1.6.1-2ubuntu1.14.04.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.6.1-2ubuntu1.14.04.1 2015-04-01 14:07:00 UTC

  libgcrypt20 (1.6.1-2ubuntu1.14.04.1) trusty-security; urgency=medium

  * SECURITY UPDATE: sidechannel attack on Elgamal
    - debian/patches/CVE-2014-3591.patch: use ciphertext blinding in
      cipher/elgamal.c.
    - CVE-2014-3591
  * SECURITY UPDATE: sidechannel attack via timing variations in mpi_powm
    - debian/patches/CVE-2015-0837.patch: avoid timing variations in
      mpi/mpi-pow.c, mpi/mpiutil.c, src/mpi.h.
    - CVE-2015-0837
 -- Marc Deslauriers <email address hidden> Thu, 26 Mar 2015 07:25:12 -0400

CVE-2014-3591 sidechannel attack on Elgamal
CVE-2015-0837 data-dependent timing variations in modular exponentiation



About   -   Send Feedback to @ubuntu_updates