libgcrypt: security bump to version 1.6.5
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Wed, 10 Feb 2016 11:06:25 +0000 (08:06 -0300)
committerPeter Korsgaard <peter@korsgaard.com>
Thu, 11 Feb 2016 22:09:12 +0000 (23:09 +0100)
Fixes:
CVE-2015-7511 - Mitigate side-channel attack on ECDH with Weierstrass
curves.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/libgcrypt/libgcrypt.hash
package/libgcrypt/libgcrypt.mk

index e845a51e95f2882c4195d4349d25cc1e59c23698..272d332353cd699df68412524a6ccf3fcde05315 100644 (file)
@@ -1,2 +1,4 @@
-# From https://lists.gnu.org/archive/html/info-gnu/2015-09/msg00000.html
-sha1 ed52add1ce635deeb2f5c6650e52667debd4ec70  libgcrypt-1.6.4.tar.bz2
+# From https://lists.gnupg.org/pipermail/gnupg-announce/2016q1/000384.html
+sha1   c3a5a13e717f7b3e3895650afc1b6e0d3fe9c726        libgcrypt-1.6.5.tar.bz2
+# Calculated based on the hash above
+sha256 f49ebc5842d455ae7019def33eb5a014a0f07a2a8353dc3aa50a76fd1dafa924        libgcrypt-1.6.5.tar.bz2
index 53d1d6cd1e473cff9dd2b4ca9a7fdc2cda450bf5..7c27a223208742ec148845e3f84cc46ab53071be 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-LIBGCRYPT_VERSION = 1.6.4
+LIBGCRYPT_VERSION = 1.6.5
 LIBGCRYPT_SOURCE = libgcrypt-$(LIBGCRYPT_VERSION).tar.bz2
 LIBGCRYPT_LICENSE = LGPLv2.1+
 LIBGCRYPT_LICENSE_FILES = COPYING.LIB