Summary: | <dev-libs/nettle-3.2: Miscalculations of elliptic curve multiplications (CVE-2015-8803,CVE-2015-8804,CVE-2015-8805) | ||||||||
---|---|---|---|---|---|---|---|---|---|
Product: | Gentoo Security | Reporter: | Hanno Böck <hanno> | ||||||
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> | ||||||
Status: | RESOLVED FIXED | ||||||||
Severity: | normal | CC: | alonbl, crypto+disabled | ||||||
Priority: | Normal | ||||||||
Version: | unspecified | ||||||||
Hardware: | All | ||||||||
OS: | Linux | ||||||||
URL: | https://blog.fuzzing-project.org/38-Miscomputations-of-elliptic-curve-scalar-multiplications-in-Nettle.html | ||||||||
Whiteboard: | B4 [noglsa] | ||||||||
Package list: | Runtime testing required: | --- | |||||||
Attachments: |
|
Description
Hanno Böck
2016-02-02 09:58:20 UTC
Created attachment 424538 [details]
nettle-3.2.ebuild
Ebuild for nettle-3.2 bumped to EAPI-6
Please check this ebuild thoroughly as I am neither very familiar with EAPI-6 nor with the involved multilib eclasses.
Created attachment 424540 [details, diff]
nettle-3.2.ebuild.diff
Diff between nettle-3.1.1 ebuild and the attached one.
What is the purpose of eap-6? We won't be able to stabilize it. (In reply to Alon Bar-Lev from comment #3) > What is the purpose of eap-6? We won't be able to stabilize it. EAPI 6 can be stabilized since portage 2.2.26 went stable on 2016-01-17 Thanks! I did not know that. Opps... this is a security bug. Version bump completed. (In reply to Alon Bar-Lev from comment #7) > Version bump completed. Thank you. Arches, please stabilize =dev-libs/nettle-3.2 Stable targets: alpha amd64 arm hppa ia64 ppc ppc64 sparc x86 Stable on alpha. amd64 stable x86 stable Stable for PPC64. Stable for HPPA. arm stable ppc stable sparc stable ia64 stable. Maintainer(s), please cleanup. Security, please vote. Cleaned up. |