]> code.ossystems Code Review - openembedded-core.git/commit
libgcrypt: CVE-2018-0495
authorJagadeesh Krishnanjanappa <jkrishnanjanappa@mvista.com>
Wed, 22 Aug 2018 11:41:53 +0000 (17:11 +0530)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Wed, 29 Aug 2018 14:22:27 +0000 (15:22 +0100)
commite05c9b1be8e852293dfc7026f0e3178c3bc5444d
tree69885fc427e6b58de5692a2e92611649b55211d4
parenta523bc6a2ff7d5b5415a789de02fb055ccd2c077
libgcrypt: CVE-2018-0495

ecc: Add blinding for ECDSA.

* cipher/ecc-ecdsa.c (_gcry_ecc_ecdsa_sign): Blind secret D with
randomized nonce B.

Signed-off-by: Armin Kuster <akuster808@gmail.com>
meta/recipes-support/libgcrypt/files/CVE-2018-0495.patch [new file with mode: 0644]
meta/recipes-support/libgcrypt/libgcrypt_1.8.2.bb