Critical vulnerability in libgcrypt 1.9.0

On January 28, a 0-day vulnerability was discovered vulnerability in the cryptographic library libgcrypt by Tavis Ormandy from Project Zero (a security team at Google that seeks 0-day vulnerabilities).

Only version 1.9.0 is affected (now renamed on the upstream FTP server to avoid accidental downloads). Due to incorrect assumptions in the code, a buffer overflow is possible, potentially leading to remote code execution. The overflow can occur during data decryption before verification and signature checking, facilitating exploitation.

Version 1.9.1 with the fix was released the next day after the vulnerability was reported. The bug arose from an unsuccessful optimization of the hash writing function nearly 2 years ago.

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster