File _patchinfo of Package patchinfo.4897

<patchinfo incident="4897">
  <issue id="991464" tracker="bnc">VUL-0: CVE-2016-6489: libnettle: RSA code is vulnerable to cache-timing related attacks</issue>
  <issue id="2016-6489" tracker="cve" />
  <category>security</category>
  <rating>moderate</rating>
  <packager>pmonrealgonzalez</packager>
  <description>This update for libnettle fixes the following issues:

-  CVE-2016-6489:
  * Reject invalid RSA keys with even modulo.
  * Check for invalid keys, with even p, in dsa_sign().
  * Use function mpz_powm_sec() instead of mpz_powm() (bsc#991464).
</description>
  <summary>Security update for libnettle</summary>
</patchinfo>
openSUSE Build Service is sponsored by