Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-9526

Опубликовано: 11 июн. 2017
Источник: debian
EPSS Низкий

Описание

In Libgcrypt before 1.7.7, an attacker who learns the EdDSA session key (from side-channel observation during the signing process) can easily recover the long-term secret key. 1.7.7 makes a cipher/ecc-eddsa.c change to store this session key in secure memory, to ensure that constant-time point operations are used in the MPI library.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libgcrypt20fixed1.7.6-2package
libgcrypt11not-affectedpackage

Примечания

  • master: https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=5a22de904a0a366ae79f03ff1e13a1232a89e26b

  • 1.7.x: https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=f9494b3f258e01b6af8bd3941ce436bcc00afc56

  • Curve Ed25519 signing and verification inplemented in 1.6.0 with

  • https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=bc5199a02abe428ad377443280b3eda60141a1d6

  • and following refactorings.

EPSS

Процентиль: 70%
0.00651
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 8 лет назад

In Libgcrypt before 1.7.7, an attacker who learns the EdDSA session key (from side-channel observation during the signing process) can easily recover the long-term secret key. 1.7.7 makes a cipher/ecc-eddsa.c change to store this session key in secure memory, to ensure that constant-time point operations are used in the MPI library.

CVSS3: 5.9
redhat
больше 8 лет назад

In Libgcrypt before 1.7.7, an attacker who learns the EdDSA session key (from side-channel observation during the signing process) can easily recover the long-term secret key. 1.7.7 makes a cipher/ecc-eddsa.c change to store this session key in secure memory, to ensure that constant-time point operations are used in the MPI library.

CVSS3: 5.9
nvd
больше 8 лет назад

In Libgcrypt before 1.7.7, an attacker who learns the EdDSA session key (from side-channel observation during the signing process) can easily recover the long-term secret key. 1.7.7 makes a cipher/ecc-eddsa.c change to store this session key in secure memory, to ensure that constant-time point operations are used in the MPI library.

suse-cvrf
больше 8 лет назад

Security update for libgcrypt

suse-cvrf
больше 8 лет назад

Security update for libgcrypt

EPSS

Процентиль: 70%
0.00651
Низкий