USN-3347-1: Libgcrypt vulnerabilities
USN-3347-1: Libgcrypt vulnerabilities Ubuntu Security Notice USN-3347-1 3rd July, 2017 libgcrypt11, libgcrypt20 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in Libgcrypt. Software description libgcrypt11 – LGPL Crypto library libgcrypt20 – LGPL Crypto library Details Daniel J. Bernstein, Joachim Breitner, Daniel Genkin, Leon GrootBruinderink, Nadia Heninger, Tanja Lange, Christine van Vredendaal, andYuval Yarom discovered that Libgcrypt was susceptible to an attack viaside channels. A local attacker could use this attack to recover RSAprivate keys. (CVE-2017-7526) It was discovered that Libgcrypt was susceptible to an attack viaside channels. A local attacker could use this attack to possibly recoverEdDSA private keys. This issue only applied to Ubuntu 16.04 LTS, Ubuntu16.10 and Ubuntu 17.04. (CVE-2017-9526) Update instructions The problem can be corrected by [ more… ]