Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

perl-Crypt-DSA-1.17-31.el9 RPM for noarch

From EPEL 9 Testing for ppc64le / Packages / p

Name: perl-Crypt-DSA Distribution: Fedora Project
Version: 1.17 Vendor: Fedora Project
Release: 31.el9 Build date: Fri Jul 3 20:01:17 2026
Group: Unspecified Build host: buildhw-x86-04.rdu3.fedoraproject.org
Size: 81064 Source RPM: perl-Crypt-DSA-1.17-31.el9.src.rpm
Packager: Fedora Project
Url: https://metacpan.org/release/Crypt-DSA
Summary: Perl module for DSA signatures and key generation
Crypt::DSA is an implementation of the DSA (Digital Signature Algorithm)
signature verification system. This package provides DSA signing, signature
verification, and key generation.

DSA (Digital Signature Algorithm) signatures are no longer considered to be
adequate for security. This module should only be used for verifying old
signatures and should not be used for new signatures. That being said, some
technologies still require DSA signatures even now. Consider using other
solutions or explicitly not using DSA signatures.

Provides

Requires

License

GPL-1.0-or-later OR Artistic-1.0-Perl

Changelog

* Fri Jul 03 2026 Paul Howarth <paul@city-fan.org> - 1.17-31
  - Hardening: Use a fresh, independent CSPRNG witness every round
  - Security fix: Modulo bias in key generation (CVE-2026-14570); an attack
    with hundreds of signatures could lead to full private-key compromise;
    keys should be considered compromised and new keys should be generated
* Mon Jun 15 2026 Paul Howarth <paul@city-fan.org> - 1.17-30
  - Fix key material reuse for multiple signing events (CVE-2026-12205, CWE-323)
* Mon May 18 2026 Paul Howarth <paul@city-fan.org> - 1.17-29
  - Replace use of cryptographically-insecure rand() function (CVE-2026-8700);
    use Crypt::URandom instead, which has a backend that calls getrandom() on
    Linux
  - Avoid use of 2-argument open() (CVE-2026-8704)
  - Fix "Use of uninitialized value $cur_part in hash element" warning in
    Crypt::DSA::KeyChain
  - Add security note discouraging use of Crypt::DSA
  - Fix typo in Crypt::DSA::Util
  - Use SPDX-format license tag

Files

/usr/share/doc/perl-Crypt-DSA
/usr/share/doc/perl-Crypt-DSA/Changes
/usr/share/doc/perl-Crypt-DSA/README
/usr/share/licenses/perl-Crypt-DSA
/usr/share/licenses/perl-Crypt-DSA/LICENSE
/usr/share/man/man3/Crypt::DSA.3pm.gz
/usr/share/man/man3/Crypt::DSA::Key.3pm.gz
/usr/share/man/man3/Crypt::DSA::Key::PEM.3pm.gz
/usr/share/man/man3/Crypt::DSA::Key::SSH2.3pm.gz
/usr/share/man/man3/Crypt::DSA::KeyChain.3pm.gz
/usr/share/man/man3/Crypt::DSA::Signature.3pm.gz
/usr/share/man/man3/Crypt::DSA::Util.3pm.gz
/usr/share/perl5/vendor_perl/Crypt
/usr/share/perl5/vendor_perl/Crypt/DSA
/usr/share/perl5/vendor_perl/Crypt/DSA.pm
/usr/share/perl5/vendor_perl/Crypt/DSA/Key
/usr/share/perl5/vendor_perl/Crypt/DSA/Key.pm
/usr/share/perl5/vendor_perl/Crypt/DSA/Key/PEM.pm
/usr/share/perl5/vendor_perl/Crypt/DSA/Key/SSH2.pm
/usr/share/perl5/vendor_perl/Crypt/DSA/KeyChain.pm
/usr/share/perl5/vendor_perl/Crypt/DSA/Signature.pm
/usr/share/perl5/vendor_perl/Crypt/DSA/Util.pm


Generated by rpm2html 1.8.1

Fabrice Bellet, Sat Jul 11 04:10:25 2026