Package        : libgcrypt20
Version        : 1.6.3-2+deb8u5
CVE ID         : CVE-2018-0495

It was discovered that Libgcrypt is prone to a local side-channel attack
allowing recovery of ECDSA private keys.

For Debian 8 "Jessie", these problems have been fixed in version
1.6.3-2+deb8u5.

We recommend that you upgrade your libgcrypt20 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-1405-1: libgcrypt20 security update

June 29, 2018
It was discovered that Libgcrypt is prone to a local side-channel attack allowing recovery of ECDSA private keys

Summary

We recommend that you upgrade your libgcrypt20 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
Package : libgcrypt20
Version : 1.6.3-2+deb8u5
CVE ID : CVE-2018-0495

Related News