[Buildroot] [PATCH] libgcrypt: security bump to version to version 1.7.3

Baruch Siach baruch at tkos.co.il
Thu Aug 18 07:40:17 UTC 2016


Hi Peter,

On Thu, Aug 18, 2016 at 09:20:27AM +0200, Peter Korsgaard wrote:
> >>>>> "Baruch" == Baruch Siach <baruch at tkos.co.il> writes:
> 
>  > Fixes CVE-2016-6316: Bug in the mixing functions of Libgcrypt's random number
>  > generator. An attacker who obtains 4640 bits from the RNG can trivially
>  > predict the next 160 bits of output.
> 
> Committed, thanks.
> 
> The announcement also talks about a new gnupg release. Will you also
> send a bump to 1.4.21?

I missed that. Just sent a patch.

baruch

-- 
     http://baruch.siach.name/blog/                  ~. .~   Tk Open Systems
=}------------------------------------------------ooO--U--Ooo------------{=
   - baruch at tkos.co.il - tel: +972.52.368.4656, http://www.tkos.co.il -



More information about the buildroot mailing list