USN-2896-1: Libgcrypt vulnerability
15 February 2016
Libgcrypt could be made to expose sensitive information.
Releases
Packages
- libgcrypt11 - LGPL Crypto library
- libgcrypt20 - LGPL Crypto library
Details
Daniel Genkin, Lev Pachmanov, Itamar Pipman and Eran Tromer discovered
that Libgcrypt was susceptible to an attack via physical side channels. A
local attacker could use this attack to possibly recover private keys.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 15.10
Ubuntu 14.04
Ubuntu 12.04
In general, a standard system update will make all the necessary changes.