openSUSE-RU-2019:1146-1: moderate: Security update for libnettle
openSUSE Recommended Update: Security update for libnettle ______________________________________________________________________________ Announcement ID: openSUSE-RU-2019:1146-1 Rating: moderate References: #1129598 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that has one recommended fix can now be installed. Description: This update for libnettle to version 3.4.1 fixes the following issues: Issues addressed and new features: - Updated to 3.4.1 (fate#327114 and bsc#1129598) - Fixed a missing break statements in the parsing of PEM input files in pkcs1-conv. - Fixed a link error on the pss-mgf1-test which was affecting builds without public key support. - All functions using RSA private keys are now side-channel silent. This applies both to the bignum calculations, which now use GMP's mpn_sec_* family of functions, and the processing of PKCS#1 padding needed for RSA decryption. - Changes in behavior: The functions rsa_decrypt and rsa_decrypt_tr may now clobber all of the provided message buffer, independent of the actual message length. They are side-channel silent, in that branches and memory accesses don't depend on the validity or length of the message. Side-channel leakage from the caller's use of length and return value may still provide an oracle useable for a Bleichenbacher-style chosen ciphertext attack. Which is why the new function rsa_sec_decrypt is recommended. This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Recommended Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-1146=1 Package List: - openSUSE Leap 15.0 (i586 x86_64): libhogweed4-3.4.1-lp150.8.1 libhogweed4-debuginfo-3.4.1-lp150.8.1 libnettle-debugsource-3.4.1-lp150.8.1 libnettle-devel-3.4.1-lp150.8.1 libnettle6-3.4.1-lp150.8.1 libnettle6-debuginfo-3.4.1-lp150.8.1 nettle-3.4.1-lp150.8.1 nettle-debuginfo-3.4.1-lp150.8.1 - openSUSE Leap 15.0 (x86_64): libhogweed4-32bit-3.4.1-lp150.8.1 libhogweed4-32bit-debuginfo-3.4.1-lp150.8.1 libnettle-devel-32bit-3.4.1-lp150.8.1 libnettle6-32bit-3.4.1-lp150.8.1 libnettle6-32bit-debuginfo-3.4.1-lp150.8.1 References: https://bugzilla.suse.com/1129598
participants (1)
-
maintenance@opensuse.org