intel / cryptography-primitives

Apache License 2.0
318 stars 86 forks source link

When will have Intel TA-00600 issue Update #38

Closed depiaro closed 2 years ago

depiaro commented 2 years ago

Hi Sir,

I got the info that IPP will public the update for vulnerability issue(TA-00600). May I know the plan of that? Below are the info I got :

Initial Publish Date: 01/04/2022 Target Public Date: 02/08/2022 Title: Intel® IPP Cryptography Advisory Intel ID: INTEL-TA-00600 Reference: RDC# 710096 Advisory Category: Software Impact of Vulnerability: Information Disclosure Summary: A potential security vulnerability in the Intel® Integrated Performance Primitives (IPP) Cryptography software library may allow information disclosure. Intel is releasing software updates to mitigate this potential vulnerability

Affected Products: Intel® IPP Crypto library before version 2021.2. Recommendation: Intel recommends updating Intel® IPP Crypto library to version 2021.2 or later. Updates are available for download at this location: https://github.com/intel/ipp-crypto

aduev commented 2 years ago

Intel® Integrated Performance Primitives Cryptography 2021.2 has been updated to include functional and security updates, including the mitigation for this issue. A public Security Advisory for this issue is scheduled to be published in the first half of February 2022. Users should update to the latest version.

depiaro commented 2 years ago

Got it. Thanks