Re: serious flaw in libgcrypt?

Thomas Biege <[email protected]> Wed, 5 Jul 2017 08:28:18 +0200
Newsgroups gmane.linux.suse.security
Organization SUSE Linux GmbH / SUSE LLC
Message-ID <[email protected]>
Good morning,

the attack is not that critical as it needs local access by the
attacker. If you have local access why not opening a X pop-up and asking
for the key phrase, thunderbird and enigmail do this very frequently and
a user wouldn't be suspicious.


On 04.07.17 18:59, Mathias Homann wrote:
> Hi guys,
> 
> https://lists.gnupg.org/pipermail/gnupg-announce/2017q2/000408.html
> and https://www.heise.de/security/meldung/Seitenkanalangriff-RSA-Verschluesselung-der-GnuPG-Kryptobibliothek-geknackt-3762957.html (in german)
> 
> Do we have that in Leap 42.2? Will we get that?
> 
> Cheers
> MH
> 


Viele Grüße / Best regards
Thomas
-- 
Thomas Biege <[email protected]>, Team Lead MaintenanceSecurity, CSSLP
https://www.suse.com/security

SUSE Linux GmbH
GF: Felix Imendörffer, Jane Smithard, Graham Norton
HRB 21284 (AG Nuernberg)
signature.asc (application/pgp-signature, 455 B)
-----BEGIN PGP SIGNATURE-----

iQEcBAEBCAAGBQJZXIcJAAoJEJqHoVJVjr8DLvcIANJQJLYSybUjuLXHJWNYFDmA
fWJkcZ6MTfVe2st7/QRBxOaYqbFwH2ak/MeZhEPuV+jVro7RA4Nro79M5OT9WL9i
qbo/O0DA5yNYbdDiR3YmKShdAGhHq6dhJSm8ZQaxLkvzR/EiFU1VTtVHk4Zlq5Bc
lKNk4YLn1QviLcOXU45lDCVPBgzxApuIq7Wwap4KKyCMl7mp4bqBnUfa1ORINud6
ipvmy7udtSWfVheRCmM8o5e0NPIU94ANOuPm0Hji/RPxzipgc9fcT3PE9+/8DwA+
z3Ti3oVcHzRMVRrAShExZWV77zKI5PS3e/4xjICFFfZalegD2455NZMfh6ygAI8=
=fqg4
-----END PGP SIGNATURE-----