GNU bug report logs

#31831 CVE-2018-0495 Key Extraction Side Channel in Multiple Crypto Libraries

PackageSource(s)Maintainer(s)
guix PTS Buildd Popcon
Full log

Message #8 received at 31831@debbugs.gnu.org (full text, mbox, reply):

Received: (at 31831) by debbugs.gnu.org; 14 Jun 2018 19:50:53 +0000
From debbugs-submit-bounces@debbugs.gnu.org Thu Jun 14 15:50:52 2018
Received: from localhost ([127.0.0.1]:48474 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces@debbugs.gnu.org>)
	id 1fTYGi-0002Bs-Mk
	for submit@debbugs.gnu.org; Thu, 14 Jun 2018 15:50:52 -0400
Received: from out2-smtp.messagingengine.com ([66.111.4.26]:56573)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <leo@famulari.name>) id 1fTYGh-0002Bl-01
 for 31831@debbugs.gnu.org; Thu, 14 Jun 2018 15:50:51 -0400
Received: from compute4.internal (compute4.nyi.internal [10.202.2.44])
 by mailout.nyi.internal (Postfix) with ESMTP id AE8EC21C4F;
 Thu, 14 Jun 2018 15:50:50 -0400 (EDT)
Received: from mailfrontend1 ([10.202.2.162])
 by compute4.internal (MEProxy); Thu, 14 Jun 2018 15:50:50 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=famulari.name;
 h=content-type:date:from:message-id:mime-version:subject:to
 :x-me-sender:x-me-sender:x-sasl-enc; s=mesmtp; bh=zfBKph5LHkMuAT
 KnpxgqnLUDVD8EIm6csHqNzKzrTbc=; b=KLjFdV2uM8AFHPHWBvUb1ScBwSVuM1
 zv+3MHtNvSFKpduZNbyrQW3n46BQkECW3OCjdiRAw+C2bK51RFSNWSGb4uX5fOsC
 jxpTU/ua/hCAIa5FgRI6SbLzCgqfBE7pG5aZgjYfJvHTjoNDp1o663TnTH2c+lWe
 S7im7nAJEm5lg=
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=
 messagingengine.com; h=content-type:date:from:message-id
 :mime-version:subject:to:x-me-sender:x-me-sender:x-sasl-enc; s=
 fm3; bh=zfBKph5LHkMuATKnpxgqnLUDVD8EIm6csHqNzKzrTbc=; b=e3ByQ0rR
 pRZGll65qQZGK1M8ygy5GkDclUUIB84R9946F5+A2fKyP/jETzmzoYdfN98w178P
 TIyLcZPeq8Np0mclTa8i3OQO1FYEmenLn+CfPBN0EQYq6bVv9aMO4vFxhi7ICelN
 HOMQa5lLIkaIkshI2RNuzEvJGDKH1NCefCtIolFqLkIdmEuirgMheqRw/M9CLQzQ
 QPLLe+qWVJUpsdRjailIEwohW+53AfNFGkQ+Wjwkx9GMdgc4PrUqSShu7rJuEsda
 MgTb9jycFlgZ4taK5UNtkJW9VWx663z7s6Np/AqdR3gRdFjjiP537nYfJ+WydDDN
 4RF+vGjTP0fyvg==
X-ME-Proxy: <xmx:GsciWxG7g_IvUN-Pz4iK79HH3Hzr8_A1IK1nUvTqRUG2N48BE1LQVg>
 <xmx:GsciW6rXa2tDMgCIny-cN43vYWBv6E4pHPqMXkLuRUMxUq2VhiNelA>
 <xmx:GsciWyRC-rixDaSyK5w3TDuy3K30QRD9uZD5d8NKJkG8bU_-wUI_mg>
 <xmx:GsciW_N4_HzrnqzRvcmZrfstcRZsi9QJsiYc6A1JBpWclkNK3Uel7w>
 <xmx:GsciW9PZq3qLGXwEbSHRNfSIlM8h41O77oR_kABdu6Q1DawK6P82kQ>
 <xmx:GsciW3vYnJayE44oX1ux2OotymFsphq-31C3wzGpJPxbNWSZujy9Vw>
X-ME-Sender: <xms:GsciW1SJ7pLbIfKmu1SzvCJQPGq9vNJF2EGz-3PIHr8O1sT8owTAqg>
Received: from localhost (c-76-124-202-137.hsd1.pa.comcast.net
 [76.124.202.137])
 by mail.messagingengine.com (Postfix) with ESMTPA id 4DFBFE4919
 for <31831@debbugs.gnu.org>; Thu, 14 Jun 2018 15:50:50 -0400 (EDT)
Date: Thu, 14 Jun 2018 15:50:49 -0400
From: Leo Famulari <leo@famulari.name>
To: 31831@debbugs.gnu.org
Subject: CVE-2018-0495 Key Extraction Side Channel in Multiple Crypto Libraries
Message-ID: <20180614195049.GB4039@jasmine.lan>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha256;
 protocol="application/pgp-signature"; boundary="J/dobhs11T7y2rNN"
Content-Disposition: inline
User-Agent: Mutt/1.10.0 (2018-05-17)
X-Spam-Score: -0.7 (/)
X-Debbugs-Envelope-To: 31831
X-BeenThere: debbugs-submit@debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit@debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request@debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces@debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org>
X-Spam-Score: -1.7 (-)
[Message part 1 (text/plain, inline)]
I see that Efraim already updated libgcrypt. Awesome, thanks Efraim!

I'll try OpenSSL next.
[signature.asc (application/pgp-signature, inline)]

Send a report that this bug log contains spam.


debbugs.gnu.org maintainers <help-debbugs@gnu.org>. Last modified: Sat Dec 21 18:28:10 2024; Machine Name: wallace-server

GNU bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.