[MacPorts] #46987: Security update: libgcrypt 1.6.3

MacPorts noreply at macports.org
Fri Feb 27 13:02:25 PST 2015


#46987: Security update: libgcrypt 1.6.3
---------------------------------+--------------------------------
 Reporter:  mschamschula@…       |      Owner:  macports-tickets@…
     Type:  update               |     Status:  new
 Priority:  Normal               |  Milestone:
Component:  ports                |    Version:  2.3.3
 Keywords:  haspatch maintainer  |       Port:  libgcrypt
---------------------------------+--------------------------------
 libgcrypt has been updated to version 1.6.3:
 {{{
 Noteworthy changes in version 1.6.3
 ===================================

 * Use ciphertext blinding for Elgamal decryption [CVE-2014-3591].
   See http://www.cs.tau.ac.il/~tromer/radioexp/ for details.

 * Fixed data-dependent timing variations in modular exponentiation
   [related to CVE-2015-0837, Last-Level Cache Side-Channel Attacks
   are Practical].

 * Improved asm support for older toolchains.
 }}}

 Also (re-)added sha1 hash as it is used in release announcements.

-- 
Ticket URL: <https://trac.macports.org/ticket/46987>
MacPorts <https://www.macports.org/>
Ports system for OS X


More information about the macports-tickets mailing list