Mageia alert MGASA-2018-0306 (libcrypt)
From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
To: | updates-announce@ml.mageia.org | |
Subject: | [updates-announce] MGASA-2018-0306: Updated libcrypt packages fix a security vulnerability | |
Date: | Mon, 2 Jul 2018 00:18:32 +0200 | |
Message-ID: | <20180701221832.A01379FEEE@duvel.mageia.org> |
MGASA-2018-0306 - Updated libcrypt packages fix a security vulnerability Publication date: 01 Jul 2018 URL: https://advisories.mageia.org/MGASA-2018-0306.html Type: security Affected Mageia releases: 5 CVE: CVE-2018-0495 Description: Updated libgcrypt packages fix security vulnerability: When libgcrypt uses the private key to create a signature, such as for a TLS or SSH connection, it inadvertently leaks information through memory caches. An unprivileged attacker running on the same machine can collect the information from a few thousand signatures and recover the value of the private ECDSA or DSA key (CVE-2018-0495). References: - https://bugs.mageia.org/show_bug.cgi?id=23210 - https://lists.gnupg.org/pipermail/gnupg-announce/2018q2/0... - https://www.nccgroup.trust/us/our-research/technical-advi... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0495 SRPMS: - 5/core/libgcrypt-1.5.4-5.5.mga5