Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Fedora 27: FEDORA-2018-a0a356fb68 Critical: Cryptopp Security Update

fedora
Calendar Grey March 6, 2018
Dist Fedora Esm H88
The latest Fedora 27 update for the cryptopp library resolves several security vulnerabilities, improves efficiency, and boosts interoperability.
Update cryptopp to 5.6.5 security release

Summary

Crypto++ Library is a free C++ class library of cryptographic schemes.

See for a list of supported algorithms.

One purpose of Crypto++ is to act as a repository of public domain

(not copyrighted) source code. Although the library is copyrighted as a

compilation, the individual files in it are in the public domain.

Update cryptopp to 5.6.5 security release. * fixed CVE-2016-7420 (Issue 277,

document NDEBUG for production/release) * fixed CVE-2016-7544 (Issue 302, avoid

_malloca and _freea for MSC compilers) * Shipped library in recommended state

backwards compatibility achieved with * improved Testing and QA

[ 1 ] Bug #1376698 - CVE-2016-7420 cryptopp: Library documentation lacks treatment of -DNDEBUG and Static Initialization [epel-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1376698

[ 2 ] Bug #1376697 - CVE-2016-7420 cryptopp: Library documentation lacks treatment of -DNDEBUG and Static Initialization [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1376697

[ 3 ] Bug #1375180 - CryptoPP::CMAC_Base::Update assert failed with tegrarcm

https://bugzilla.redhat.com/show_bug.cgi?id=1375180

[ 4 ] Bug #1401407 - Cryptopp 5.6.5 released, Fedora Rawhide currently on 5.6.3

https://bugzilla.redhat.com/show_bug.cgi?id=1401407

su -c 'dnf upgrade cryptopp' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 27
Version: 5.6.5
Release: 2.fc27
URL: Summary : C++ class library of cryptographic schemes

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here