USN-4236-3: Libgcrypt vulnerability
USN-4236-3: Libgcrypt vulnerability libgcrypt11 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 ESM Ubuntu 12.04 ESM Summary Libgcrypt could be made to expose sensitive information. Software Description libgcrypt11 – LGPL Crypto library Details USN-4236-1 fixed a vulnerability in Libgcrypt. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: It was discovered that Libgcrypt was susceptible to a ECDSA timing attack. An attacker could possibly use this attack to recover sensitive information. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM libgcrypt11 – 1.5.3-2ubuntu4.6+esm1 Ubuntu 12.04 ESM libgcrypt11 – 1.5.0-3ubuntu0.9 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References USN-4236-1 CVE-2019-13627 Source: USN-4236-3: Libgcrypt [ more… ]