First published: Sun Aug 27 2017(Updated: )
Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.c.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libgcrypt20 | <=1.8.0-1<=1.7.1-1 | 1.8.1-1 1.7.9-1 1.7.6-2+deb9u2 |
GnuPG Libgcrypt | <=1.8.0 | |
Debian Debian Linux | =9.0 | |
debian/libgcrypt20 | 1.8.7-6 1.10.1-3 1.11.0-2 1.11.0-5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.