Opened 9 years ago

Closed 9 years ago

#46987 closed update (fixed)

libgcrypt @1.6.2_0: update to 1.6.3

Reported by: Schamschula (Marius Schamschula) Owned by: larryv (Lawrence Velázquez)
Priority: Normal Milestone:
Component: ports Version:
Keywords: haspatch maintainer Cc:
Port: libgcrypt

Description

libgcrypt has been updated to version 1.6.3:

Noteworthy changes in version 1.6.3 
===================================

* Use ciphertext blinding for Elgamal decryption [CVE-2014-3591].
  See http://www.cs.tau.ac.il/~tromer/radioexp/ for details.

* Fixed data-dependent timing variations in modular exponentiation
  [related to CVE-2015-0837, Last-Level Cache Side-Channel Attacks
  are Practical].

* Improved asm support for older toolchains.

Also (re-)added sha1 hash as it is used in release announcements.

Attachments (1)

Portfile-libgcrypt.diff (828 bytes) - added by Schamschula (Marius Schamschula) 9 years ago.

Download all attachments as: .zip

Change History (3)

Changed 9 years ago by Schamschula (Marius Schamschula)

Attachment: Portfile-libgcrypt.diff added

comment:1 Changed 9 years ago by larryv (Lawrence Velázquez)

Owner: changed from macports-tickets@… to larryv@…
Status: newassigned
Summary: Security update: libgcrypt 1.6.3libgcrypt @1.6.2_0: update to 1.6.3
Version: 2.3.3

Thanks.

comment:2 Changed 9 years ago by larryv (Lawrence Velázquez)

Resolution: fixed
Status: assignedclosed
Note: See TracTickets for help on using tickets.