Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Phong Nguyen identified a severe bug in the way GnuPG creates anduses ElGamal keys, when those keys are used both to sign and encryptdata. This vulnerability can be used to trivially recover theprivate key. . ---------------------------------------------------------------------Fedora Security Update Notification FEDORA-2003-025 2003-12-10 ---------------------------------------------------------------------Name : gnupg Version : 1.2.3 Release : 2 Summary : A GNU utility for secure communication and data storage. Description : GnuPG (GNU Privacy Guard) is a GNU utility for encrypting data and creating digital signatures. GnuPG has advanced key management capabilities and is compliant with the proposed OpenPGP Internet standard described in RFC2440. Since GnuPG doesn't use any patented algorithm, it is not compatible with any version of PGP2 (PGP2.x uses only IDEA for symmetric-key encryption, which is patented worldwide). ---------------------------------------------------------------------Update Information: Phong Nguyen identified a severe bug in the way GnuPG creates and uses ElGamal keys, when those keys are used both to sign and encrypt data. This vulnerability can be used to trivially recover the private key. While the default behavior of GnuPG when generating keys does not lead to the creation of unsafe keys, by overriding the default settings an unsafe key could have been created. If you are using ElGamal keys, you should revoke those keys immediately. The packages included in this update do not make ElGamal keys safe to use; they merely include a patch by David Shaw that disables functions that would generate or use ElGamal keys for encryption. ---------------------------------------------------------------------* Mon Dec 01 2003 Nalin Dahyabhai 1.2.3-2 - incorporate patch from gnupg-announce which removes the ability to create ElGamal encrypt+sign keys or to sign messages with such keys *Mon Oct 27 2003 Nalin Dahyabhai 1.2.3-1 - use -fPIE instead of -fpie because some arches need it * Mon Oct 27 2003 Nalin Dahyabhai - build gnupg as a position-independent executable (Arjan van de Ven) * Mon Aug 25 2003 Nalin Dahyabhai - add Werner's key as a source file * Fri Aug 22 2003 Nalin Dahyabhai - update to 1.2.3 ---------------------------------------------------------------------This update can be downloaded from: b7457d205b1807677a352f734dd794b4 SRPMS/gnupg-1.2.3-2.src.rpm b8d2688e98330f98e954ccffaf0aed79 i386/gnupg-1.2.3-2.i386.rpm 86b34157605dd65bd369d39a7b9d8ea2 i386/debug/gnupg-debuginfo-1.2.3-2.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- . OpenSSL poses a considerable threat regarding certificate management; prompt actions to restrict RSA key usage are crucial and imperative for protection.. GnuPG, ElGamal, key exposure, Fedora update, security patch. . Severity: Critical. LinuxSecurity.com Team
Multiple security vulnerabilities have been discovered in mbedtls, a lightweight crypto and SSL/TLS library, which may allow attackers to obtain sensitive information like the RSA private key or cause a denial of service (application or server crash). . -------------------------------------------------------------------------Debian LTS Advisory DLA-3249-1
A flaw was discovered in tang, a network-based cryptographic binding server, which could result in leak of private keys. For the stable distribution (bullseye), this problem has been fixed in . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5025-1
Multiple vulnerabilities have been found in GnuPG and libgcrypt, the worst of which may allow a local attacker to obtain confidential key information. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201606-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: GnuPG: Multiple vulnerabilities Date: June 05, 2016 Bugs: #534110, #541564, #541568 ID: 201606-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in GnuPG and libgcrypt, the worst of which may allow a local attacker to obtain confidential key information. Background ========= The GNU Privacy Guard, GnuPG, is a free replacement for the PGP suite of cryptographic software. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-crypt/gnupg < 2.0.26-r3 *> = 1.4.19 > = 2.0.26-r3 2 dev-libs/libgcrypt < 1.6.3-r4 > = 1.6.3-r4 ------------------------------------------------------------------- 2 affected packages Description ========== Multiple vulnerabilities have been discovered in GnuPG and libgcrypt, please review the CVE identifiers referenced below for details. Impact ===== A local attacker could possibly cause a Denial of Service condition. Side-channel attacks could be leveraged to obtain key material. Workaround ========= There is no known workaround at this time. Resolution ========= All GnuPG 2 users should upgrade to the latest version: #emerge --sync # emerge --ask --oneshot --verbose "> =app-crypt/gnupg-2.0.26-r3" All GnuPG 1 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-crypt/gnupg-1.4.19" All libgcrypt users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/libgcrypt-1.6.3-r4" References ========= [ 1 ] CVE-2014-3591 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3591 [ 2 ] CVE-2015-0837 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0837 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201606-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
An update that fixes three vulnerabilities is now available.. openSUSE Security Update: Security update for openssh ______________________________________________________________________________ Announcement ID: openSUSE-SU-2016:0144-1 Rating: critical References: #961642 #961645 Cross-References: CVE-2016-077 CVE-2016-0777 CVE-2016-0778 Affected Products: openSUSE Evergreen 11.4 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: - CVE-2016-0777: A malicious or compromised server could cause the OpenSSH client to expose part or all of the client's private key through the roaming feature (bsc#961642) - CVE-2016-0778: A malicious or compromised server could could trigger a buffer overflow in the OpenSSH client through the roaming feature (bsc#961645) This update disables the undocumented feature supported by the OpenSSH client and a commercial SSH server. Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Evergreen 11.4: zypper in -t patch 2016-48=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Evergreen 11.4 (i586 x86_64): openssh-5.8p1-11.1 openssh-askpass-5.8p1-11.1 openssh-askpass-debuginfo-5.8p1-11.1 openssh-askpass-gnome-5.8p1-11.1 openssh-askpass-gnome-debuginfo-5.8p1-11.1 openssh-debuginfo-5.8p1-11.1 openssh-debugsource-5.8p1-11.1 References: https://www.suse.com/security/cve/CVE-2016-0777.html https://www.suse.com/security/cve/CVE-2016-0778.html https://bugzilla.suse.com/961642 https://bugzilla.suse.com/961645 -- . openSUSE Security Update: Security update for openssh ______________________________________________. update, security, fixes, three, vulnerabilities,opensuse. . Severity: Critical. LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.. SUSE Security Update: Security update for openssh ______________________________________________________________________________ Announcement ID: SUSE-SU-2016:0120-1 Rating: critical References: #961642 #961645 Cross-References: CVE-2016-0777 CVE-2016-0778 Affected Products: SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Desktop 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for openssh fixes the following issues: - CVE-2016-0777: A malicious or compromised server could cause the OpenSSH client to expose part or all of the client's private key through the roaming feature (bsc#961642) - CVE-2016-0778: A malicious or compromised server could could trigger a buffer overflow in the OpenSSH client through the roaming feature (bsc#961645) This update disables the undocumented feature supported by the OpenSSH client and a commercial SSH server. Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-openssh-2016011302-12326=1 - SUSE Linux Enterprise Desktop 11-SP4: zypper in -t patch sledsp4-openssh-2016011302-12326=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-openssh-2016011302-12326=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): openssh-6.6p1-16.1 openssh-askpass-gnome-6.6p1-16.4 openssh-fips-6.6p1-16.1 openssh-helpers-6.6p1-16.1 - SUSE Linux Enterprise Desktop 11-SP4 (i586 x86_64): openssh-6.6p1-16.1 openssh-askpass-gnome-6.6p1-16.4 openssh-helpers-6.6p1-16.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): openssh-askpass-gnome-debuginfo-6.6p1-16.4 openssh-debuginfo-6.6p1-16.1 openssh-debugsource-6.6p1-16.1 References: https://www.suse.com/security/cve/CVE-2016-0777.html https://www.suse.com/security/cve/CVE-2016-0778.html https://bugzilla.suse.com/show_bug.cgi?id=961642 https://bugzilla.suse.com/show_bug.cgi?id=961645 . SUSE Security Patch for OpenSSH tackles urgent security threats with high-risk vulnerabilities. . SUSE Linux, openssh security, critical updates, software vulnerability. . Severity: Critical. LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.. SUSE Security Update: Security update for openssh ______________________________________________________________________________ Announcement ID: SUSE-SU-2016:0119-1 Rating: critical References: #961642 #961645 Cross-References: CVE-2016-0777 CVE-2016-0778 Affected Products: SUSE Linux Enterprise Server for VMWare 11-SP3 SUSE Linux Enterprise Server 11-SP3 SUSE Linux Enterprise Desktop 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP3 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for openssh fixes the following issues: - CVE-2016-0777: A malicious or compromised server could cause the OpenSSH client to expose part or all of the client's private key through the roaming feature (bsc#961642) - CVE-2016-0778: A malicious or compromised server could could trigger a buffer overflow in the OpenSSH client through the roaming feature (bsc#961645) This update disables the undocumented feature supported by the OpenSSH client and a commercial SSH server. Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for VMWare 11-SP3: zypper in -t patch slessp3-openssh-2016011301-12325=1 - SUSE Linux Enterprise Server 11-SP3: zypper in -t patch slessp3-openssh-2016011301-12325=1 - SUSE Linux Enterprise Desktop 11-SP3: zypper in -t patch sledsp3-openssh-2016011301-12325=1 - SUSE Linux Enterprise Debuginfo 11-SP3: zypper in -t patch dbgsp3-openssh-2016011301-12325=1 To bring your system up-to-date, use "zypperpatch". Package List: - SUSE Linux Enterprise Server for VMWare 11-SP3 (i586 x86_64): openssh-6.2p2-0.24.1 openssh-askpass-6.2p2-0.24.1 openssh-askpass-gnome-6.2p2-0.24.3 - SUSE Linux Enterprise Server 11-SP3 (i586 ia64 ppc64 s390x x86_64): openssh-6.2p2-0.24.1 openssh-askpass-6.2p2-0.24.1 openssh-askpass-gnome-6.2p2-0.24.3 - SUSE Linux Enterprise Desktop 11-SP3 (i586 x86_64): openssh-6.2p2-0.24.1 openssh-askpass-6.2p2-0.24.1 openssh-askpass-gnome-6.2p2-0.24.3 - SUSE Linux Enterprise Debuginfo 11-SP3 (i586 ia64 ppc64 s390x x86_64): openssh-askpass-gnome-debuginfo-6.2p2-0.24.3 openssh-debuginfo-6.2p2-0.24.1 openssh-debugsource-6.2p2-0.24.1 References: https://www.suse.com/security/cve/CVE-2016-0777.html https://www.suse.com/security/cve/CVE-2016-0778.html https://bugzilla.suse.com/show_bug.cgi?id=961642 https://bugzilla.suse.com/show_bug.cgi?id=961645 . Important SUSE Security Patch for OpenSSH tackles two security flaws that threaten private key secrecy and pose a buffer overflow risk.. openssh Update, SUSE Security, Server Fixes. . Severity: Critical. LinuxSecurity.com Team
Multiple vulnerabilities have been found in OpenSSL allowing remote attackers to determine private keys or cause a Denial of Service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201312-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: OpenSSL: Multiple Vulnerabilities Date: December 03, 2013 Bugs: #369753, #406199, #412643, #415435, #455592 ID: 201312-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in OpenSSL allowing remote attackers to determine private keys or cause a Denial of Service. Background ========= OpenSSL is an Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) as well as a general purpose cryptography library. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-libs/openssl < 1.0.0i *> = 0.9.8y *> = 1.0.0j 2 dev-libs/openssl < 0.9.8y Vulnerable! ------------------------------------------------------------------- NOTE: Certain packages are still vulnerable. Users should migrate to another package if one is available or wait for the existing packages to be marked stable by their architecture maintainers. ------------------------------------------------------------------- 2 affected packages Description ========== Multiple vulnerabilities have been discovered in OpenSSL. Pleasereview the CVE identifiers referenced below for details. Impact ===== Remote attackers can determine private keys, decrypt data, cause a Denial of Service or possibly have other unspecified impact. Workaround ========= There is no known workaround at this time. Resolution ========= All OpenSSL 1.0.x users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/openssl-1.0.0j" All OpenSSL 0.9.8 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/openssl-0.9.8y" References ========= [ 1 ] CVE-2006-7250 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-7250 [ 2 ] CVE-2011-1945 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1945 [ 3 ] CVE-2012-0884 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0884 [ 4 ] CVE-2012-1165 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1165 [ 5 ] CVE-2012-2110 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2110 [ 6 ] CVE-2012-2333 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2333 [ 7 ] CVE-2012-2686 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2686 [ 8 ] CVE-2013-0166 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0166 [ 9 ] CVE-2013-0169 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0169 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201312-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.