Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
197

Debian 7: DLA-1015-1 Critical Key Exposure in Libgcrypt11 Cryptography

It was discovered that there was a key disclosure vulnerability in libgcrypt11 a library of cryptographic routines: It is well known that constant-time implementations of modular exponentiation . Hash: SHA256 Package : libgcrypt11 Version : 1.5.0-5+deb7u6 CVE ID : CVE-2017-7526 It was discovered that there was a key disclosure vulnerability in libgcrypt11 a library of cryptographic routines: It is well known that constant-time implementations of modular exponentiation cannot use sliding windows. However, software libraries such as Libgcrypt, used by GnuPG, continue to use sliding windows. It is widely believed that, even if the complete pattern of squarings and multiplications is observed through a side-channel attack, the number of exponent bits leaked is not sufficient to carry out a full key-recovery attack against RSA. Specifically, 4-bit sliding windows leak only 40% of the bits, and 5-bit sliding windows leak only 33% of the bits. -- Sliding right into disaster: Left-to-right sliding windows leak For Debian 7 "Wheezy", this issue has been fixed in libgcrypt11 version 1.5.0-5+deb7u6. We recommend that you upgrade your libgcrypt11 packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'` This email address is being protected from spambots. You need JavaScript enabled to view it. / chris-lamb.co.uk `- . Libgcrypt11 security vulnerability resolved in update for Debian 7 Wheezy. Ensure to upgrade to avert potential cryptographic risks.. libgcrypt11 security, Debian update, cryptography patch, key exposure fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 06, 2017 Critical Debian LTS
87

Debian 8 DSA-3478-1 Critical: ECDH Key Leak in Libgcrypt11 Security Update

Daniel Genkin, Lev Pachmanov, Itamar Pipman and Eran Tromer discovered that the ECDH secret decryption keys in applications using the libgcrypt11 library could be leaked via a side-channel attack. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3478-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso February 15, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libgcrypt11 CVE ID : CVE-2015-7511 Daniel Genkin, Lev Pachmanov, Itamar Pipman and Eran Tromer discovered that the ECDH secret decryption keys in applications using the libgcrypt11 library could be leaked via a side-channel attack. See https://cs-people.bu.edu/tromer/ecdh/ for details. For the oldstable distribution (wheezy), this problem has been fixed in version 1.5.0-5+deb7u4. We recommend that you upgrade your libgcrypt11 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu Security Notice USN-4502-1 alerts on ECDHE key exposure through libgcrypt20. Immediate patching suggested.. libgcrypt11 update, debian security, ecdh decryption, side-channel exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 15, 2016 Critical Debian
87

Debian: DSA-3073-1 Low: Elgamal Encryption Side-Channel Attack

Daniel Genkin, Itamar Pipman and Eran Tromer discovered that Elgamal encryption subkeys in applications using the libgcrypt11 library, for example GnuPG 2.x, could be leaked via a side-channel attack. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3073-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Salvatore Bonaccorso November 16, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libgcrypt11 CVE ID : CVE-2014-5270 Daniel Genkin, Itamar Pipman and Eran Tromer discovered that Elgamal encryption subkeys in applications using the libgcrypt11 library, for example GnuPG 2.x, could be leaked via a side-channel attack. For the stable distribution (wheezy), this problem has been fixed in version 1.5.0-5+deb7u2. We recommend that you upgrade your libgcrypt11 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance your libgcrypt11 libraries: The advisory DSA-3073-1 concerns vulnerabilities in Elgamal encryption methods.. Debian Security Advisory, Libgcrypt11 Update, Side-Channel Attack. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Nov 16, 2014 Low Debian
87

Debian DSA-2731-1 Critical: Libgcrypt11 Information Leak

Yarom and Falkner discovered that RSA secret keys in applications using the libgcrypt11 library, for example GnuPG 2.x, could be leaked via a side channel attack, where a malicious local user could obtain private key information from another user on the system. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2731-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Thijs Kinkhorst July 29, 2013 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libgcrypt11 Vulnerability : information leak Problem type : local Debian-specific: no CVE ID : CVE-2013-4242 Yarom and Falkner discovered that RSA secret keys in applications using the libgcrypt11 library, for example GnuPG 2.x, could be leaked via a side channel attack, where a malicious local user could obtain private key information from another user on the system. For the oldstable distribution (squeeze), this problem has been fixed in version 1.4.5-2+squeeze1. For the stable distribution (wheezy), this problem has been fixed in version 1.5.0-5+deb7u1. For the testing distribution (jessie) and unstable distribution (sid), this problem has been fixed in version 1.5.3-1. We recommend that you upgrade your libgcrypt11 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu Security Notice USN-1234-1 reveals a critical patch addressing vulnerabilities in OpenSSL to enhance protection.. Libgcrypt11, Debian, Information Leak, Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 29, 2013 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here