A biased ECDSA nonce generation allowed an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. In other words, an adversary may already have enough signature information to compromise a victim's . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3839-1
Fixes CVE-2022-24884 (Improper Verification of ECDSA Signatures). In previous versions ecdsautils would erroneously accept all-zero signatures as valid. More information can be found here: https://github.com/freifunk-gluon/ecdsautils/security/advisories/GHSA-qhcg-9ffp-78pw. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-bf58612696 2022-05-16 02:04:05.714214 --------------------------------------------------------------------------------Name : ecdsautils Product : Fedora 35 Version : 0.4.1 Release : 1.fc35 URL : https://github.com/freifunk-gluon/ecdsautils Summary : Tiny collection of programs used for ECDSA (keygen, sign, verify) Description : This collection of ECDSA utilities can be used to sign and verify data in a simple manner. --------------------------------------------------------------------------------Update Information: Fixes CVE-2022-24884 (Improper Verification of ECDSA Signatures). In previous versions ecdsautils would erroneously accept all-zero signatures as valid. More information can be found here: https://github.com/freifunk-gluon/ecdsautils/security/advisories/GHSA-qhcg-9ffp-78pw --------------------------------------------------------------------------------ChangeLog: * Thu May 5 2022 Felix Kaechele - 0.4.1-1 - update to 0.4.1 - use new upstream URLs - drop patch now upstreamed - added libs and devel subpackages * Thu Jan 20 2022 Fedora Release Engineering - 0.3.2-18 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2082427 - CVE-2022-24884 ecdsautils: Improper Verification of ECDSA Signatures [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2082427 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade--advisory FEDORA-2022-bf58612696' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Fixes CVE-2022-24884 (Improper Verification of ECDSA Signatures). In previous versions ecdsautils would erroneously accept all-zero signatures as valid. More information can be found here: https://github.com/freifunk-gluon/ecdsautils/security/advisories/GHSA-qhcg-9ffp-78pw. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-7704d5e885 2022-05-16 01:43:34.426938 --------------------------------------------------------------------------------Name : ecdsautils Product : Fedora 34 Version : 0.4.1 Release : 1.fc34 URL : https://github.com/freifunk-gluon/ecdsautils Summary : Tiny collection of programs used for ECDSA (keygen, sign, verify) Description : This collection of ECDSA utilities can be used to sign and verify data in a simple manner. --------------------------------------------------------------------------------Update Information: Fixes CVE-2022-24884 (Improper Verification of ECDSA Signatures). In previous versions ecdsautils would erroneously accept all-zero signatures as valid. More information can be found here: https://github.com/freifunk-gluon/ecdsautils/security/advisories/GHSA-qhcg-9ffp-78pw --------------------------------------------------------------------------------ChangeLog: * Thu May 5 2022 Felix Kaechele - 0.4.1-1 - update to 0.4.1 - use new upstream URLs - drop patch now upstreamed - added libs and devel subpackages * Thu Jan 20 2022 Fedora Release Engineering - 0.3.2-18 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild * Wed Jul 21 2021 Fedora Release Engineering - 0.3.2-17 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2082427 - CVE-2022-24884 ecdsautils: Improper Verification of ECDSA Signatures [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2082427 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-7704d5e885' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Fixes CVE-2022-24884 (Improper Verification of ECDSA Signatures). In previous versions ecdsautils would erroneously accept all-zero signatures as valid. More information can be found here: https://github.com/freifunk-gluon/ecdsautils/security/advisories/GHSA-qhcg-9ffp-78pw. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-111177a5ac 2022-05-14 01:48:30.603225 --------------------------------------------------------------------------------Name : ecdsautils Product : Fedora 36 Version : 0.4.1 Release : 1.fc36 URL : https://github.com/freifunk-gluon/ecdsautils Summary : Tiny collection of programs used for ECDSA (keygen, sign, verify) Description : This collection of ECDSA utilities can be used to sign and verify data in a simple manner. --------------------------------------------------------------------------------Update Information: Fixes CVE-2022-24884 (Improper Verification of ECDSA Signatures). In previous versions ecdsautils would erroneously accept all-zero signatures as valid. More information can be found here: https://github.com/freifunk-gluon/ecdsautils/security/advisories/GHSA-qhcg-9ffp-78pw --------------------------------------------------------------------------------ChangeLog: * Thu May 5 2022 Felix Kaechele - 0.4.1-1 - update to 0.4.1 - use new upstream URLs - drop patch now upstreamed - added libs and devel subpackages --------------------------------------------------------------------------------References: [ 1 ] Bug #2082427 - CVE-2022-24884 ecdsautils: Improper Verification of ECDSA Signatures [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2082427 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-111177a5ac' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
In ecdsautils, a collection of ECDSA elliptic curve cryptography command line tools, an improper verification of cryptographic signatures was detected. A signature consisting only of zeroes is always considered valid, making it trivial to forge signatures. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2997-1
Multiple vulnerabilities were discovered in nettle, a low level cryptographic library, which could result in denial of service (remote crash in RSA decryption via specially crafted ciphertext, crash on ECDSA signature verification) or incorrect verification of ECDSA signatures. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4933-1
Updated mbedtls packages fix security vulnerability Fix side channel in ECC code that allowed an adversary with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave) to fully recover an ECDSA private key. . MGASA-2020-0265 - Updated mbedtls packages fix security vulnerability Publication date: 16 Jun 2020 URL: https://advisories.mageia.org/MGASA-2020-0265.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-10932 Updated mbedtls packages fix security vulnerability Fix side channel in ECC code that allowed an adversary with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave) to fully recover an ECDSA private key. (CVE-2020-10932) Fix a potentially remotely exploitable buffer overread in a DTLS client when parsing the Hello Verify Request message. References: - https://bugs.mageia.org/show_bug.cgi?id=26758 - https://www.trustedfirmware.org/projects/mbed-tls/ - - https://www.cve.org/CVERecord?id=CVE-2020-10932 SRPMS: - 7/core/mbedtls-2.16.6-1.mga7 . Recent updates to mbedtls packages address a critical security vulnerability in Mageia 7. It is strongly advised to act promptly to protect ECDSA keys.. Mageia Security Update, mbedtls Vulnerability, ECDSA Key Security, Buffer Overread Fix. . LinuxSecurity.com Team
- Update to 2.16.3 - Side channel attack on deterministic ECDSA (CVE-2019-16910) Release notes: https://www.trustedfirmware.org/projects/mbed-tls/ Security Advisory: . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-07940971b2 2019-10-07 00:53:40.514560 --------------------------------------------------------------------------------Name : mbedtls Product : Fedora 30 Version : 2.16.3 Release : 1.fc30 URL : https://www.trustedfirmware.org/projects/mbed-tls/ Summary : Light-weight cryptographic and SSL/TLS library Description : Mbed TLS is a light-weight open source cryptographic and SSL/TLS library written in C. Mbed TLS makes it easy for developers to include cryptographic and SSL/TLS capabilities in their (embedded) applications with as little hassle as possible. FOSS License Exception: https://www.trustedfirmware.org/projects/mbed-tls/ --------------------------------------------------------------------------------Update Information: - Update to 2.16.3 - Side channel attack on deterministic ECDSA (CVE-2019-16910) Release notes: https://www.trustedfirmware.org/projects/mbed-tls/ Security Advisory: --------------------------------------------------------------------------------ChangeLog: * Sat Sep 28 2019 Morten Stevens - 2.16.3-1 - Update to 2.16.3 - Side channel attack on deterministic ECDSA (CVE-2019-16910) * Tue Sep 3 2019 Morten Stevens - 2.16.2-4 - devel package needs pkcs11-helper-devel (#1748468) * Sat Aug 3 2019 Morten Stevens - 2.16.2-3 - Fix building on RHEL8 * Thu Jul 25 2019 Fedora Release Engineering - 2.16.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Sat Jul 20 2019 Morten Stevens - 2.16.2-1 - Update to 2.16.2 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-07940971b2' at thecommand line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.