SUSE-SU-2015:1626-1
Dashboard / Vulnerabilities / SUSE-SU-2015:1626-1
SUSE-SU-2015:1626-1
Summary: Security update for libgcrypt
Details: This update fixes the following issues: * Use ciphertext blinding for Elgamal decryption [CVE-2014-3591]. See http://www.cs.tau.ac.il/~tromer/radioexp/ for details. (bsc#920057) * Fixed data-dependent timing variations in modular exponentiation [related to CVE-2015-0837, Last-Level Cache Side-Channel Attacks are Practical]
References: https://www.suse.com/support/update/announcement/2015/suse-su-20151626-1/, https://bugzilla.suse.com/920057, https://www.suse.com/security/cve/CVE-2014-3591, https://www.suse.com/security/cve/CVE-2015-0837
Affected packages
Package
Name: libgcrypt
Purl: pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
