UbuntuUpdates.org

Package "libtomcrypt0"

Name: libtomcrypt0

Description:

public domain open source cryptographic toolkit

Latest version: 1.17-5ubuntu0.1
Release: trusty (14.04)
Level: security
Repository: universe
Head package: libtomcrypt
Homepage: http://libtom.org/

Links


Download "libtomcrypt0"


Other versions of "libtomcrypt0" in Trusty

Repository Area Version
base universe 1.17-5
updates universe 1.17-5ubuntu0.1

Changelog

Version: 1.17-5ubuntu0.1 2018-08-06 21:06:52 UTC

  libtomcrypt (1.17-5ubuntu0.1) trusty-security; urgency=medium

  * SECURITY UPDATE: Fix possible bleichenbacher signature attack.
    - debian/patches/CVE-2016-6129.patch: fix in
      src/pk/rsa/rsa_verify_hash.c
    - CVE-2016-6129

  * SECURITY UPDATE: Memory side-channel attack on ECDSA signatures.
    - debian/patches/CVE-2018-12437.patch: fix in
      src/pk/ecc/ecc_sign_hash.c
    - CVE-2018-12437

 -- Eduardo Barretto <email address hidden> Mon, 06 Aug 2018 13:17:41 -0300

CVE-2016-6129 The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in OP-TEE before 2.2.0, does not validate that the message length is equ
CVE-2018-12437 LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To di



About   -   Send Feedback to @ubuntu_updates