Re: serious flaw in libgcrypt?
Thomas Biege <[email protected]> Wed, 5 Jul 2017 08:28:18 +0200
| Newsgroups | gmane.linux.suse.security |
|---|---|
| Organization | SUSE Linux GmbH / SUSE LLC |
| Message-ID | <[email protected]> |
Good morning, the attack is not that critical as it needs local access by the attacker. If you have local access why not opening a X pop-up and asking for the key phrase, thunderbird and enigmail do this very frequently and a user wouldn't be suspicious. On 04.07.17 18:59, Mathias Homann wrote: > Hi guys, > > https://lists.gnupg.org/pipermail/gnupg-announce/2017q2/000408.html > and https://www.heise.de/security/meldung/Seitenkanalangriff-RSA-Verschluesselung-der-GnuPG-Kryptobibliothek-geknackt-3762957.html (in german) > > Do we have that in Leap 42.2? Will we get that? > > Cheers > MH > Viele Grüße / Best regards Thomas -- Thomas Biege <[email protected]>, Team Lead MaintenanceSecurity, CSSLP https://www.suse.com/security SUSE Linux GmbH GF: Felix Imendörffer, Jane Smithard, Graham Norton HRB 21284 (AG Nuernberg)
signature.asc
(application/pgp-signature, 455 B)
-----BEGIN PGP SIGNATURE----- iQEcBAEBCAAGBQJZXIcJAAoJEJqHoVJVjr8DLvcIANJQJLYSybUjuLXHJWNYFDmA fWJkcZ6MTfVe2st7/QRBxOaYqbFwH2ak/MeZhEPuV+jVro7RA4Nro79M5OT9WL9i qbo/O0DA5yNYbdDiR3YmKShdAGhHq6dhJSm8ZQaxLkvzR/EiFU1VTtVHk4Zlq5Bc lKNk4YLn1QviLcOXU45lDCVPBgzxApuIq7Wwap4KKyCMl7mp4bqBnUfa1ORINud6 ipvmy7udtSWfVheRCmM8o5e0NPIU94ANOuPm0Hji/RPxzipgc9fcT3PE9+/8DwA+ z3Ti3oVcHzRMVRrAShExZWV77zKI5PS3e/4xjICFFfZalegD2455NZMfh6ygAI8= =fqg4 -----END PGP SIGNATURE-----