1
0
mirror of https://git.yoctoproject.org/poky synced 2026-05-31 12:49:46 +00:00
Files
Ross Burton 3ca9f90dff libgcrypt: fix CVE-2017-9526
In libgcrypt before 1.7.7, an attacker who learns the EdDSA session key (from
side-channel observation during the signing process) can easily recover the
long-term secret key. 1.7.7 makes a cipher/ecc-eddsa.c change to store this
session key in secure memory, to ensure that constant-time point operations are
used in the MPI library.

(From OE-Core rev: fb28c54347fcf4957b9b8ee7dee423d859eb7820)

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2017-07-19 15:13:47 +01:00
..
2016-03-07 00:11:38 +00:00
2016-04-29 07:41:42 +01:00
2017-05-18 13:14:20 +01:00
2014-01-06 11:13:55 +00:00
2015-11-25 08:08:08 +00:00
2016-02-07 17:30:00 +00:00
2016-02-28 11:33:04 +00:00
2016-02-04 23:39:03 +00:00
2015-12-28 09:25:15 +00:00
2016-02-11 12:27:45 +00:00
2016-01-11 23:26:31 +00:00
2015-08-10 12:40:20 -07:00
2016-01-18 11:47:04 +00:00
2016-01-18 11:47:04 +00:00
2014-01-02 22:39:23 +00:00
2016-02-28 11:33:04 +00:00
2017-07-19 15:13:47 +01:00
2015-09-24 17:54:30 +01:00
2017-05-18 13:14:22 +01:00
2017-05-18 13:14:22 +01:00
2015-08-19 18:05:36 +01:00
2015-02-19 07:51:39 +00:00
2016-08-25 23:09:15 +01:00
2016-02-07 17:29:58 +00:00
2015-09-12 23:01:53 +01:00
2016-02-04 23:19:42 +00:00
2016-06-29 19:35:57 +01:00
2016-02-18 07:39:30 +00:00