SUSE-SU-2018:2452-2
Dashboard / Vulnerabilities / SUSE-SU-2018:2452-2
SUSE-SU-2018:2452-2
Summary: Security update for libgcrypt
Details: This update for libgcrypt fixes the following issues: The following security vulnerability was addressed: - CVE-2018-0495: Mitigate a novel side-channel attack by enabling blinding for ECDSA signatures (bsc#1097410). The following other issues were fixed: - Extended the fipsdrv dsa-sign and dsa-verify commands with the --algo parameter for the FIPS testing of DSA SigVer and SigGen (bsc#1064455). - Ensure libgcrypt20-hmac and libgcrypt20 are installed in the correct order. (bsc#1090766)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20182452-2/, https://bugzilla.suse.com/1064455, https://bugzilla.suse.com/1090766, https://bugzilla.suse.com/1097410, https://www.suse.com/security/cve/CVE-2018-0495
Affected packages
Package
Name: libgcrypt
Purl: pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
