GNU bug report logs

#31831 CVE-2018-0495 Key Extraction Side Channel in Multiple Crypto Libraries

PackageSource(s)Maintainer(s)
guix PTS Buildd Popcon
Full log

Message #42 received at 31831-done@debbugs.gnu.org (full text, mbox, reply):

Received: (at 31831-done) by debbugs.gnu.org; 26 Feb 2019 02:01:17 +0000
From debbugs-submit-bounces@debbugs.gnu.org Mon Feb 25 21:01:17 2019
Received: from localhost ([127.0.0.1]:52027 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces@debbugs.gnu.org>)
	id 1gyS3Y-0001A7-Qr
	for submit@debbugs.gnu.org; Mon, 25 Feb 2019 21:01:17 -0500
Received: from out2-smtp.messagingengine.com ([66.111.4.26]:38039)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <leo@famulari.name>) id 1gyS3X-00019v-Ne
 for 31831-done@debbugs.gnu.org; Mon, 25 Feb 2019 21:01:16 -0500
Received: from compute4.internal (compute4.nyi.internal [10.202.2.44])
 by mailout.nyi.internal (Postfix) with ESMTP id 7E8FF22167;
 Mon, 25 Feb 2019 21:01:10 -0500 (EST)
Received: from mailfrontend2 ([10.202.2.163])
 by compute4.internal (MEProxy); Mon, 25 Feb 2019 21:01:10 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=famulari.name;
 h=date:from:cc:subject:message-id:references:mime-version
 :content-type:in-reply-to; s=mesmtp; bh=2oZr+RPGx0HainMEjU3ctZRA
 oIeVgjOGKfWTuAjvtXc=; b=bZpN0jN3fYAwOwRzzBt1psMKbcDft10WWQ5rRdY0
 oQok5vAJVgdH5vQnrczT9vZSq3jVeJC4W6wNi7sLxbuyE5b1HEaVkTIOI/RdcvaW
 +AEsoksHvYTXM56qyRODRoo/GLhiqsLINNkeb0RYPE3oMmDvrLB/5IWBWO/kDXSl
 6k8=
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=
 messagingengine.com; h=cc:content-type:date:from:in-reply-to
 :message-id:mime-version:references:subject:x-me-proxy
 :x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm2; bh=2oZr+R
 PGx0HainMEjU3ctZRAoIeVgjOGKfWTuAjvtXc=; b=OdmSvqZJjW68HGJqmXBcsg
 5Si+oxGW3XiXdt1U9108XEdNmTY1r6qs7qzO+wlijbA9yPlacshHibsN5083N2ek
 gzj+NY9CmVLOTTrYBIUF2WOoH8QK1HpREuu5MuBMHFJtUXXQW1KKCeDueqVdUtgn
 BCuHEzHXuDULdhdeCxN1k7jfcS9yNoLZlnJ5Y87ywHQxLFgizpK22+3ZK3rRbUkp
 DcXQBF4HTDbIotbGAusdiHZQfGVJtG1gyjbfmrlrwbJhI7ZlRyk2xJ+vJ1atNA3g
 UF7u7CxzvLdhpwX/wCo8R0etrqN5AgpgX22zp4RlttQ+TOZlQcMDc9neJjsUjBiw
 ==
X-ME-Sender: <xms:5p10XNpCODmtBcHqTiUV4WSBJPtJaJwG_vGGiYGhlw7OEulXGs-dGg>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedutddrudekgdegudculddtuddrgedtledrtddtmd
 cutefuodetggdotefrodftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpqfhuthen
 uceurghilhhouhhtmecufedttdenuchmihhsshhinhhgucfvqfcufhhivghlugculdeftd
 dmnecujfgurhepfffhuffkfhggtggujggfsehgtderredtredvnecuhfhrohhmpefnvgho
 ucfhrghmuhhlrghrihcuoehlvghosehfrghmuhhlrghrihdrnhgrmhgvqeenucffohhmrg
 hinhepghhithhhuhgsrdgtohhmpdgtrhihphhtohhpphdrtghomhenucfkphepjeeirddu
 vdegrddvtddvrddufeejnecurfgrrhgrmhepmhgrihhlfhhrohhmpehlvghosehfrghmuh
 hlrghrihdrnhgrmhgvnecuvehluhhsthgvrhfuihiivgeptd
X-ME-Proxy: <xmx:5p10XOlXJyoVrGR8F7WfXJzOA8jGGfwiTSzL7xvVYhId4hJW6CKJqQ>
 <xmx:5p10XGQ3Mphp1PqIuWxjHb_iT2uZbqggZj3-zv__LaxCksaV9uQmGQ>
 <xmx:5p10XMbdOBS3n4Ftmmoo-Kuz-vlE0Ast8XwJfcNyacaObaY_S1keew>
 <xmx:5p10XOM2sWiEBpDua3JBiqRy-oD9wivhuOLcnm-EwjyFvaPjlYOZRg>
Received: from localhost (c-76-124-202-137.hsd1.pa.comcast.net
 [76.124.202.137])
 by mail.messagingengine.com (Postfix) with ESMTPA id CE46810338
 for <31831-done@debbugs.gnu.org>; Mon, 25 Feb 2019 21:01:09 -0500 (EST)
Date: Mon, 25 Feb 2019 21:01:08 -0500
From: Leo Famulari <leo@famulari.name>
Subject: Re: bug#31831: CVE-2018-0495 Key Extraction Side Channel in Multiple
 Crypto Libraries
Message-ID: <20190226020108.GA25161@jasmine.lan>
References: <20180614195049.GB4039@jasmine.lan>
 <20180716062034.GA3973@jasmine.lan>
 <CAE4v=pi3GY239AEQYS4MmYgjBo-kHoA3+gx5TN009fcR_gmneQ@mail.gmail.com>
 <20180716171430.GA20978@jasmine.lan>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha256;
 protocol="application/pgp-signature"; boundary="qDbXVdCdHGoSgWSk"
Content-Disposition: inline
In-Reply-To: <20180716171430.GA20978@jasmine.lan>
User-Agent: Mutt/1.11.3 (2019-02-01)
X-Spam-Score: 0.5 (/)
X-Debbugs-Envelope-To: 31831-done
Cc: 31831-done@debbugs.gnu.org
X-BeenThere: debbugs-submit@debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit@debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request@debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces@debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org>
X-Spam-Score: -0.5 (/)
[Message part 1 (text/plain, inline)]
On Mon, Jul 16, 2018 at 01:14:30PM -0400, Leo Famulari wrote:
> There is a new release of Crypto++ available. I'm not sure if this
> addresses whatever issue was mentioned in the original advisory.

Crypto++ was updated to 8.0.0 in January 2019.

https://www.cryptopp.com/release800.html

> mbedTLS's changelog doesn't mention anything related to key extraction
> side channels.

mbedTLS has been updated several times since this bug was opened, and is
currently at 2.16.0.

https://github.com/ARMmbed/mbedtls/blob/fb1972db23da39bd11d4f9c9ea6266eee665605b/ChangeLog

Neither of those upstreams have mentioned CVE-2018-0495, as far as I can
tell. The original advisory said they do not use the vulnerable pattern,
but do use "non-constant math, but different pattern".

Overall, I don't think there is anything left for us to do as a distro
in response to CVE-2018-0495, so I am closing this bug.
[signature.asc (application/pgp-signature, inline)]

Send a report that this bug log contains spam.


debbugs.gnu.org maintainers <help-debbugs@gnu.org>. Last modified: Sat Dec 21 18:39:28 2024; Machine Name: wallace-server

GNU bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.