Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-0379

Опубликовано: 29 авг. 2017
Источник: debian
EPSS Низкий

Описание

Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.c.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libgcrypt20fixed1.7.9-1package
libgcrypt20not-affectedjessiepackage
libgcrypt11not-affectedpackage

Примечания

  • https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commitdiff;h=da780c8183cccc8f533c8ace8211ac2cb2bdee7b

  • https://eprint.iacr.org/2017/806

EPSS

Процентиль: 83%
0.01856
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.c.

CVSS3: 4.4
redhat
больше 8 лет назад

Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.c.

CVSS3: 7.5
nvd
больше 8 лет назад

Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.c.

CVSS3: 7.5
github
больше 3 лет назад

Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.c.

EPSS

Процентиль: 83%
0.01856
Низкий