Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Tue, 8 Sep 2015 12:05:34 +0200
From: Marcus Meissner <meissner@...e.de>
To: OSS Security List <oss-security@...ts.openwall.com>,
	cve-assign@...re.org
Subject: CVE Request: libgcrypt hardening for RSA-CRT leak

Hi,

Redhat has published a paper on RSA-CRT keyleakage.

https://securityblog.redhat.com/2015/09/02/factoring-rsa-keys-with-tls-perfect-forward-secrecy/

There was a CVE assigned for this issue CVE-2015-5738, but the software scope of this assigned is not clear.

libgcrypt has published a hardening fix for the same issue.
https://lists.gnupg.org/pipermail/gnupg-announce/2015q3/000370.html
http://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=b85c8d6645039fc9d403791750510e439731d479

Should it get a new CVE?

Ciao, Marcus

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.