BSDSec

deadsimple BSD Security Advisories and Announcements

OpenBSD Errata: November 17th, 2018 (blinding)

Errata patches for libcrypto have been released for OpenBSD 6.3.

Timing side channels may leak information about DSA and ECDSA private keys.

Binary updates for the amd64, i386, and arm64 platforms are available
via the syspatch utility. Source code patches can be found on the errata
page:

  https://www.openbsd.org/errata63.html

Users compiling from source should also rebuild the statically linked
binary /sbin/isakmpd if it is to be used.