libgcrypt: security bump to version 1.6.3
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Sat, 28 Feb 2015 11:09:12 +0000 (08:09 -0300)
committerPeter Korsgaard <peter@korsgaard.com>
Sat, 28 Feb 2015 12:03:54 +0000 (13:03 +0100)
Fixes:
CVE-2014-3591 - Use ciphertext blinding for Elgamal decryption
CVE-2015-0837 - Fixed data-dependent timing variations in modular
exponentiation.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/libgcrypt/libgcrypt.hash
package/libgcrypt/libgcrypt.mk

index 2ce7a67c924e9da6ca5b8c4524d00bd7eca64519..9cad1c49b19803537527442444e69f4d65906704 100644 (file)
@@ -1,2 +1,2 @@
-# From http://lists.gnupg.org/pipermail/gnupg-announce/2014q3/000355.html
-sha1   cc31aca87e4a3769cb86884a3f5982b2cc8eb7ec        libgcrypt-1.6.2.tar.bz2
+# From http://lists.gnupg.org/pipermail/gnupg-announce/2015q1/000364.html
+sha1   9456e7b64db9df8360a1407a38c8c958da80bbf1        libgcrypt-1.6.3.tar.bz2
index 4d64da8807076482f63e635c1cc412632b87a56e..e2a4b392eafcae08209b01f3a5b2cf28da800d8b 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-LIBGCRYPT_VERSION = 1.6.2
+LIBGCRYPT_VERSION = 1.6.3
 LIBGCRYPT_SOURCE = libgcrypt-$(LIBGCRYPT_VERSION).tar.bz2
 LIBGCRYPT_LICENSE = LGPLv2.1+
 LIBGCRYPT_LICENSE_FILES = COPYING.LIB