Your message dated Sun, 27 Aug 2017 11:49:39 +0000
with message-id <[email protected]>
and subject line Bug#873383: fixed in libgcrypt20 1.8.1-1
has caused the Debian Bug report #873383,
regarding libgcrypt20: CVE-2017-0379: side-channel attack on Curve25519
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
873383: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=873383
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libgcrypt20
Version: 1.7.1-1
Severity: grave
Tags: upstream patch security fixed-upstream

Hi,

the following vulnerability was published for libgcrypt20.

CVE-2017-0379[0]:
side-channel attack on Curve25519

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-0379
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0379
[1] 
https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=da780c8183cccc8f533c8ace8211ac2cb2bdee7b

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: libgcrypt20
Source-Version: 1.8.1-1

We believe that the bug you reported is fixed in the latest version of
libgcrypt20, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Andreas Metzler <[email protected]> (supplier of updated libgcrypt20 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 27 Aug 2017 13:13:01 +0200
Source: libgcrypt20
Binary: libgcrypt20-doc libgcrypt20-dev libgcrypt20 libgcrypt20-udeb 
libgcrypt11-dev libgcrypt-mingw-w64-dev
Architecture: source
Version: 1.8.1-1
Distribution: experimental
Urgency: medium
Maintainer: Debian GnuTLS Maintainers <[email protected]>
Changed-By: Andreas Metzler <[email protected]>
Closes: 873297 873383
Description: 
 libgcrypt11-dev - transitional libgcrypt11-dev package
 libgcrypt20-dev - LGPL Crypto library - development files
 libgcrypt20-doc - LGPL Crypto library - documentation
 libgcrypt20 - LGPL Crypto library - runtime library
 libgcrypt20-udeb - LGPL Crypto library - runtime library (udeb)
 libgcrypt-mingw-w64-dev - LGPL Crypto library - Windows development
Changes:
 libgcrypt20 (1.8.1-1) experimental; urgency=medium
 .
   * New upstream version.
     + Mitigates a local side-channel attack on Curve25519 dubbed "May the
       Fourth be With You".  [CVE-2017-0379] Closes: #873383
     + Add the OID SHA384WithECDSA from RFC-7427 to SHA-384. Closes: 873297
   * Use @ARCHIVE_EXT@ in watchfile instead of hardcoding bz2.
Checksums-Sha1: 
 a0b7bf430034ee0f69f280db9530b3e8ae51344d 2914 libgcrypt20_1.8.1-1.dsc
 dd35f00da45602afe81e01f4d60c40bbdd826fe6 2967344 libgcrypt20_1.8.1.orig.tar.bz2
 e8af8fc95cab49aeff13e1ef450603785c22f1b1 310 libgcrypt20_1.8.1.orig.tar.bz2.asc
 3618938fe1ec3e398c2b139d72889fde572db2f7 27220 
libgcrypt20_1.8.1-1.debian.tar.xz
Checksums-Sha256: 
 5e4c0be1f9cb7b94476ee6198d8d03d4cc30b0af658af865b9b1ab9bc556234f 2914 
libgcrypt20_1.8.1-1.dsc
 7a2875f8b1ae0301732e878c0cca2c9664ff09ef71408f085c50e332656a78b3 2967344 
libgcrypt20_1.8.1.orig.tar.bz2
 9e08f467824855084594a14c4a0455963dac9a359d543e8c2a91ca3498ad031b 310 
libgcrypt20_1.8.1.orig.tar.bz2.asc
 0b26c83d902a3cc624ea743ae2cd2a08a6cd2b433d6c424497058afef3a49a15 27220 
libgcrypt20_1.8.1-1.debian.tar.xz
Files: 
 c343f9d2a71cc76f24baec1738342680 2914 libs optional libgcrypt20_1.8.1-1.dsc
 b21817f9d850064d2177285f1073ec55 2967344 libs optional 
libgcrypt20_1.8.1.orig.tar.bz2
 7da7be1dae72e715e5b5fd10373d6155 310 libs optional 
libgcrypt20_1.8.1.orig.tar.bz2.asc
 d2224f0e5320131120d0c55e2c844129 27220 libs optional 
libgcrypt20_1.8.1-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE0uCSA5741Jbt9PpepU8BhUOCFIQFAlmirHUACgkQpU8BhUOC
FITnRg//RQRg3fYdwnvjxPtDIRtjXyln7tWvaJljjwOagYCsMTFv8lzNJg3+sZGx
Gg1PyLeNYvB0qeefuu/B8vCufQQz6xDfUrSmD25p7EwXcubzetUlHBBtxlwMrNr4
cg6U03jE64DM238o27kyn56z064tO9Fo1nmF9OXijUZx1ugmYEvMT1gR0G49YKZ3
y3Blth/wJLLddMmsHRRcKGDpWOI4wlJ+77T1Yx5pbrDDygIzBugFT9G9Wr0Dr+C+
XHXTDmHlRDC11Cg9UaS7h7Fur8mZMsWLV+4mv6ySCMXpe1mZYU6GUhmR5D7ngm4g
+qH+nL39IL1xvF8VAPPIflbwGVe9AximGFU/sPOoqB8Hk/wXMjV2nhU2+KrrBnlS
jMsdP8EqTSW+YqCLqIzLnDKpL/EnLPzKg+DX0Ij7WSQLM6Clrbd4gPCostgG9M4A
S9+os+FaKC8TXdnH1nOS+Fdgm4T9s6G+8PmRv+cCOrbRMFT2OaSLwSHInD7QQeeT
zKlltRs0SDezuwb6wNlUb/xp0BPfw+giE9AKoTDPrjdLpiRQjiPnckwnc+K+TJw1
kM4FN5WaJA3Xf1qHp529DxN7fWhrTu1sDJQtXRbBIZ3sVzzz2M+m0nnQX6R70iQ/
qUJKDVIgONZnjCo72d6tMW9erLIDhxOI9bNlfXyz7jMzScx3/as=
=RKmY
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to