From 8ea7d3a2d4a8e6457ee162c8923d5b72946a71a711c5d35e4476ba36d6b3aedd Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tom=C3=A1=C5=A1=20Chv=C3=A1tal?= Date: Thu, 31 Aug 2017 08:01:22 +0000 Subject: [PATCH] Accepting request 519788 from home:AndreasStieger:branches:devel:libraries:c_c++ libgcrypt 1.8.1 libgcrypt 1.8.1 CVE-2017-0379 bsc#1055837 OBS-URL: https://build.opensuse.org/request/show/519788 OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libgcrypt?expand=0&rev=102 --- libgcrypt-1.8.0.tar.bz2 | 3 --- libgcrypt-1.8.0.tar.bz2.sig | Bin 620 -> 0 bytes libgcrypt-1.8.1.tar.bz2 | 3 +++ libgcrypt-1.8.1.tar.bz2.sig | Bin 0 -> 310 bytes libgcrypt.changes | 11 +++++++++++ libgcrypt.spec | 2 +- 6 files changed, 15 insertions(+), 4 deletions(-) delete mode 100644 libgcrypt-1.8.0.tar.bz2 delete mode 100644 libgcrypt-1.8.0.tar.bz2.sig create mode 100644 libgcrypt-1.8.1.tar.bz2 create mode 100644 libgcrypt-1.8.1.tar.bz2.sig diff --git a/libgcrypt-1.8.0.tar.bz2 b/libgcrypt-1.8.0.tar.bz2 deleted file mode 100644 index 72aa433..0000000 --- a/libgcrypt-1.8.0.tar.bz2 +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:23e49697b87cc4173b03b4757c8df4314e3149058fa18bdc4f82098f103d891b -size 2963266 diff --git a/libgcrypt-1.8.0.tar.bz2.sig b/libgcrypt-1.8.0.tar.bz2.sig deleted file mode 100644 index 38cd9485363bd974efda8687b5affa087f25a44731cf60aec294ab4651ce1968..0000000000000000000000000000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 620 zcmV-y0+aoT0W$;u0SEvc79j-KX(1!T23_i24?49Zn>o@?CF8aQ0$FYu000UJ5G0#9 z(oZGhwoz>d|3unvk*YO+e2(Qvcfx)pxEUIkDt+YocmLFCHe@TUyr2k6e0t<2{8hEW zk+eyz=(({vtn#U;)Q|4UCg^-kny5O6js(d*fEz|yn4JVXo%#JbuWI{p!+VP^I}iX0 z&D47l%;j{~A`*mi!g}an`zkf%ag%tSHq439F|QXj%cunIzOA`&N%!iodp6aS-Pur= zDD+r`p{Bz6bWT7ws}^ZAoqFtF1E<5YZgEGQ@@>5b-4B+UJv!gI@vaRGz%#w#X9Kim zMNxYwu(5+tL*yGts%oBt=Q8J2Nk8n3pOctR2lj!*ZsYm^7?gw^EN2#68rg%%wZ;HS zH&hSLg^2+(1ONdD038+~1OpzzQ*Kxdj-rOC@*r`riZi`G1_c6HZxHYR3JDM(aj=Rr zy*~z)7YF_!+j^9`_wM*8&ob&})(aEZ>CLtZd>Zd$*9sUa|9et|n&vY_5wtU_GnO&G z)=<&KGW(HJvRO9?pe{dG6sl7}(SrZ}F!0luDRYnw8|4_dfh7@Jn_t@FRM0+>(buqL z*)$rnY9R<5QP9rMyBJN#AflkqLnoOrRq_IxylDfUmU&oPxS6|0Aq}5}K_#L79#9CF z2hf4sb96;)rV1UlnE~7cibITHcZ^ncVX- z;9-MPx%FrDC9ECo*6TydwLFEQ+9*%3%x~=nHaB+QUaBHVkxo@?CF8aQ0$HMUX#ffd5G0#9 z(oZGhwulM{0HV0mRIheb<6aMr-^r z4C$RIB#I2;L0OZS`@wn3k1Um`i1cuLXkuw* z;bD61f|W`ja3JhUUjV06Ui`z9I6$5bK*Ar&wRc%Z!O|nwtNb;{+Aj*VGJ4!KjPO@dkBzs*-^m zRW+S=caKO;OrLEg?@Fjw@PzuSCJ^T42@IloEXWGQM3KO`J`e=BiLLyaXLN!ecoTti Ie#vZaklLz@t^fc4 literal 0 HcmV?d00001 diff --git a/libgcrypt.changes b/libgcrypt.changes index 11d2f19..2a7fb95 100644 --- a/libgcrypt.changes +++ b/libgcrypt.changes @@ -1,3 +1,14 @@ +------------------------------------------------------------------- +Mon Aug 28 17:54:24 UTC 2017 - astieger@suse.com + +- libgcrypt 1.8.1: + * Mitigate a local side-channel attack on Curve25519 dubbed "May + the Fourth be With You" CVE-2017-0379 bsc#1055837 + * Add more extra bytes to the pool after reading a seed file + * Add the OID SHA384WithECDSA from RFC-7427 to SHA-384 + * Fix build problems with the Jitter RNG + * Fix assembler code build problems on Rasbian (ARMv8/AArch32-CE) + ------------------------------------------------------------------- Mon Jul 24 23:43:40 UTC 2017 - jengelh@inai.de diff --git a/libgcrypt.spec b/libgcrypt.spec index 6d5e466..ec793b2 100644 --- a/libgcrypt.spec +++ b/libgcrypt.spec @@ -21,7 +21,7 @@ %define libsoname %{name}20 %define cavs_dir %{_libexecdir}/%{name}/cavs Name: libgcrypt -Version: 1.8.0 +Version: 1.8.1 Release: 0 Summary: The GNU Crypto Library License: GPL-2.0+ AND LGPL-2.1+ AND GPL-3.0+