Re: [SECURITY] [DLA 1931-1] libgcrypt20 security update

2019-09-25 Thread Salvatore Bonaccorso
Hi Chris, On Wed, Sep 25, 2019 at 02:27:43PM +0100, Chris Lamb wrote: > Hi Salvatore, > > > > > For Debian 8 "Jessie", this issue has been fixed in libgcrypt20 version > > > 1.6.3-2+deb8u6. > […] > > Just a heads-up in case not seen yet: For all (but the amd64 upload) > > it looks there were FTB

Re: [SECURITY] [DLA 1931-1] libgcrypt20 security update

2019-09-25 Thread Chris Lamb
Hi Salvatore, > > For Debian 8 "Jessie", this issue has been fixed in libgcrypt20 version > > 1.6.3-2+deb8u6. […] > Just a heads-up in case not seen yet: For all (but the amd64 upload) > it looks there were FTBFS: Thanks for the explicit notice. I addressed this in libgcrypt20 1.6.3-2+deb8u7.

Re: [SECURITY] [DLA 1931-1] libgcrypt20 security update

2019-09-24 Thread Salvatore Bonaccorso
Hi Chris, On Tue, Sep 24, 2019 at 04:40:52PM +0100, Chris Lamb wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Package: libgcrypt20 > Version: 1.6.3-2+deb8u6 > CVE ID : CVE-2019-13627 > Debian Bug : #938938 > > It was discovered that there was a ECDSA t