Advisories ยป MGASA-2018-0306

Updated libcrypt packages fix a security vulnerability

Publication date: 01 Jul 2018
Type: security
Affected Mageia releases : 5
CVE: CVE-2018-0495

Description

Updated libgcrypt packages fix security vulnerability:

When libgcrypt uses the private key to create a signature, such as for a TLS or
SSH connection, it inadvertently leaks information through memory caches. An
unprivileged attacker running on the same machine can collect the information
from a few thousand signatures and recover the value of the private ECDSA or
DSA key (CVE-2018-0495).
                

References

SRPMS

5/core