|
|
Log in / Subscribe / Register

Arch Linux alert ASA-201709-14 (lib32-libgcrypt)

From:  Levente Polyak <anthraxx@archlinux.org>
To:  arch-security@archlinux.org
Subject:  [arch-security] [ASA-201709-14] lib32-libgcrypt: private key recovery
Date:  Mon, 18 Sep 2017 16:38:39 +0200
Message-ID:  <ab252080-626b-fb27-3d65-512c78cdae6d@archlinux.org>

Arch Linux Security Advisory ASA-201709-14 ========================================== Severity: Medium Date : 2017-09-18 CVE-ID : CVE-2017-0379 Package : lib32-libgcrypt Type : private key recovery Remote : No Link : https://security.archlinux.org/AVG-403 Summary ======= The package lib32-libgcrypt before version 1.8.1-1 is vulnerable to private key recovery. Resolution ========== Upgrade to 1.8.1-1. # pacman -Syu "lib32-libgcrypt>=1.8.1-1" The problem has been fixed upstream in version 1.8.1. Workaround ========== None. Description =========== Libgcrypt before 1.8.1 does not properly consider Curve25519 side- channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.c. On multi user systems or on boxes with virtual machines this attack may be used to steal private keys. Impact ====== On a multi user system or on boxes with virtual machines a local attacker may be able to perform a side-channel attack to steal private keys. References ========== https://lists.gnupg.org/pipermail/gnupg-announce/2017q3/0... https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;... https://eprint.iacr.org/2017/806 https://security.archlinux.org/CVE-2017-0379


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds