Advisories ยป MGASA-2018-0301

Updated libgcrypt packages fix security vulnerability

Publication date: 01 Jul 2018
Modification date: 01 Jul 2018
Type: security
Affected Mageia releases : 6
CVE: CVE-2018-0495

Description

When libgcrypt uses the private key to create a signature, such as for a
TLS or SSH connection, it inadvertently leaks information through memory
caches. An unprivileged attacker running on the same machine can collect
the information from a few thousand signatures and recover the value of
the private ECDSA or DSA key (CVE-2018-0495).
                

References

SRPMS

6/core