|
Message-ID: <20150908100534.GC18322@suse.de> Date: Tue, 8 Sep 2015 12:05:34 +0200 From: Marcus Meissner <meissner@...e.de> To: OSS Security List <oss-security@...ts.openwall.com>, cve-assign@...re.org Subject: CVE Request: libgcrypt hardening for RSA-CRT leak Hi, Redhat has published a paper on RSA-CRT keyleakage. https://securityblog.redhat.com/2015/09/02/factoring-rsa-keys-with-tls-perfect-forward-secrecy/ There was a CVE assigned for this issue CVE-2015-5738, but the software scope of this assigned is not clear. libgcrypt has published a hardening fix for the same issue. https://lists.gnupg.org/pipermail/gnupg-announce/2015q3/000370.html http://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=b85c8d6645039fc9d403791750510e439731d479 Should it get a new CVE? Ciao, Marcus
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.