Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.maint.java > #8671

Re: Bug: #802671 CVE-2015-7940 bouncycastle: ECC private keys can be recovered via invalid curve attack

From Markus Koschany <apo@debian.org>
Newsgroups linux.debian.maint.java
Subject Re: Bug: #802671 CVE-2015-7940 bouncycastle: ECC private keys can be recovered via invalid curve attack
Date 2015-12-13 23:00 +0100
Message-ID <qFmQq-5ro-5@gated-at.bofh.it> (permalink)
References <qFmQq-5ro-7@gated-at.bofh.it> <qFmQq-5ro-9@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Am 13.12.2015 um 21:37 schrieb Luciano Bello:
[...]
> They look good. Just make sure you use the version+debXuY format for the
> wheezy version too (in this case 1.44+dfsg-3.1+deb7u1, iinm).
> 
> Dont forget to use -sa since is the first build for security.
> 
> 
> Feel free to upload them after fixing this.

Done.

Regards,

Markus


Back to linux.debian.maint.java | Previous | Next | Find similar


Thread

Re: Bug: #802671 CVE-2015-7940 bouncycastle: ECC private keys can be  recovered via invalid curve attack Markus Koschany <apo@debian.org> - 2015-12-13 23:00 +0100

csiph-web