Bug#901626: libtomcrypt: CVE-2018-12437

2018-06-15 Thread Michael Stapelberg
Filed https://github.com/libtom/libtomcrypt/issues/407, let’s see when upstream comes up with a patch. On Fri, Jun 15, 2018 at 9:22 PM, Salvatore Bonaccorso wrote: > Source: libtomcrypt > Version: 1.18.1-1 > Severity: grave > Tags: security upstream > > Hi, > > The following vulnerability was

Bug#901626: libtomcrypt: CVE-2018-12437

2018-06-15 Thread Salvatore Bonaccorso
Source: libtomcrypt Version: 1.18.1-1 Severity: grave Tags: security upstream Hi, The following vulnerability was published for libtomcrypt. CVE-2018-12437[0]: | LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on | ECDSA signatures, aka the Return Of the Hidden Number