Accepting request 935053 from home:AndreasStieger:branches:devel:libraries:c_c++

CVE-2021-40529 boo#1190244

OBS-URL: https://build.opensuse.org/request/show/935053
OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/Botan?expand=0&rev=109
This commit is contained in:
Pedro Monreal Gonzalez 2021-12-02 12:54:24 +00:00 committed by Git OBS Bridge
parent 2aadc8f2c5
commit fff33fb6e7

View File

@ -4,7 +4,7 @@ Wed Nov 24 20:02:41 UTC 2021 - Dirk Müller <dmueller@suse.com>
- update to 2.18.2: - update to 2.18.2:
* Avoid using short exponents when encrypting in ElGamal, as some PGP * Avoid using short exponents when encrypting in ElGamal, as some PGP
implementations generate keys with parameters that are weak when implementations generate keys with parameters that are weak when
short exponents are used short exponents are used CVE-2021-40529 boo#1190244
* Fix a low risk OAEP decryption side channel * Fix a low risk OAEP decryption side channel
* Work around a miscompilation of SHA-3 caused by a bug in Clang 12 * Work around a miscompilation of SHA-3 caused by a bug in Clang 12
and XCode 13 and XCode 13