HomeFreeBSD

security/libgcrypt: update to 1.8.1

Description

security/libgcrypt: update to 1.8.1

  • Update libgcrypt to 1.8.1
  • Bump library version in pkg-plist

Noteworthy changes in version 1.8.1

  • Bug fixes:
    • Mitigate a local side-channel attack on Curve25519 dubbed "May the Fourth be With You". [CVE-2017-0379] [also in 1.7.9]
    • Add more extra bytes to the pool after reading a seed file.
    • Add the OID SHA384WithECDSA from RFC-7427 to SHA-384.
    • Fix build problems with the Jitter RNG
    • Fix assembler code build problems on Rasbian (ARMv8/AArch32-CE).

Changes: https://abi-laboratory.pro/tracker/changelog/libgcrypt/1.8.1/log.html
Binary compatibility report: https://abi-laboratory.pro/tracker/compat_report/libgcrypt/1.8.0/1.8.1/31172/abi_compat_report.html

MFH: 2017Q3
Security: https://vuxml.freebsd.org/freebsd/22f28bb3-8d98-11e7-8c37-e8e0b747a45a.html

Details

Provenance
cpmAuthored on
Parents
rP448988: Document libgcrypt side-channel attack vulnerability
Branches
Unknown
Tags
Unknown