lp:ubuntu/trusty-security/libgcrypt20

Created by Ubuntu Package Importer and last modified
Get this branch:
bzr branch lp:ubuntu/trusty-security/libgcrypt20
Members of Ubuntu branches can upload to this branch. Log in for directions.

Branch merges

Related bugs

Related blueprints

Branch information

Owner:
Ubuntu branches
Review team:
Ubuntu Development Team
Status:
Mature

Recent revisions

9. By Marc Deslauriers

* SECURITY UPDATE: sidechannel attack on Elgamal
  - debian/patches/CVE-2014-3591.patch: use ciphertext blinding in
    cipher/elgamal.c.
  - CVE-2014-3591
* SECURITY UPDATE: sidechannel attack via timing variations in mpi_powm
  - debian/patches/CVE-2015-0837.patch: avoid timing variations in
    mpi/mpi-pow.c, mpi/mpiutil.c, src/mpi.h.
  - CVE-2015-0837

8. By Adam Conrad

debian/rules: Drop from -O3 to -O2 to work around FTBFS on ppc64el.

7. By Andreas Metzler <email address hidden>

libgcrypt20-dev does not provide libgcrypt-dev anymore and conflicts with
libgcrypt11-dev in addition to the virtual package libgcrypt-dev.
The previous setup of having libgcryptXX-dev provide/conflict
libgcrypt-dev breaks for packages build-depending on the virtual package.
Closes: #741959

6. By Andreas Metzler <email address hidden>

* New upstream version.
  + New member in gcry_md_flags, bump dependency version of gcry_md_open().
  + GCRYCTL_INACTIVATE_FIPS_FLAG/GCRYCTL_REACTIVATE_FIPS_FLAG reserved but
    returning a GPG_ERR_NOT_IMPLEMENTED yet. Bump dependency version of
    gcry_control().
* Fix c'n'p error in Vcs-Git field. Closes: #737022

5. By Matthias Klose

Add blowfish-arm.S and serpent-armv7-neon.S, not included in the
upstream release.

4. By Matthias Klose

Don't try to build blowfish-arm, not included in the sources.

3. By Andreas Metzler <email address hidden>

* Upload to unstable.
* Add description to 12_lessdeps_libgcrypt-config.diff.

2. By Andreas Metzler <email address hidden>

* Point vcs* to git.
* New upstream version.
  + Update symbol file.
  + Rename all (including -dev) packages to match soname bump. Because of
    API changes gnutls26 cannot be built against gcrypt 1.6.0. As we are not
    ready to drop gnutls26 and it seems unlikely that gnutls upstream makes
    feature changes to its old-old-old-stable release we will need to keep
    the old gcrypt development package around.
  + Don't build udeb for the time being.
  + Update version of libgpg-error-dev build-dependency.
* Drop Breaks with old, gcrypt-1.5.x incompatible versions of gnupg2, gpgsm
  and libgnutls26.
* Ship hmac256.1 in libgcrypt20-dev.
* Add debian/upstream-signing-key.pgp (listed in
  debian/source/include-binaries) and update watchfile to check
  upstream signature.
* Edit "image path" entries in info docs to point /usr/share/doc/.../html.
* Replace /usr/share/doc/libgcrypt20-dbg with a symlink to
  /usr/share/doc/libgcrypt20.

1. By Andreas Metzler <email address hidden>

Import upstream version 1.6.0

Branch metadata

Branch format:
Branch format 7
Repository format:
Bazaar repository format 2a (needs bzr 1.16 or later)
Stacked on:
lp:ubuntu/vivid/libgcrypt20
This branch contains Public information 
Everyone can see this information.

Subscribers