USN-3417-1: Libgcrypt vulnerability

14 September 2017

Libgcrypt could be made to expose sensitive information.

Releases

Packages

Details

Daniel Genkin, Luke Valenta, and Yuval Yarom discovered that Libgcrypt was
susceptible to an attack via side channels. A local attacker could use this
attack to recover Curve25519 private keys.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 17.04

In general, a standard system update will make all the necessary changes.

References