Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-2236

Опубликовано: 06 мар. 2024
Источник: debian
EPSS Низкий

Описание

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libgcrypt20unfixedpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2268268

  • https://lists.gnupg.org/pipermail/gcrypt-devel/2024-March/005607.html

  • https://github.com/tomato42/marvin-toolkit/tree/master/example/libgcrypt

  • https://people.redhat.com/~hkario/marvin/

  • https://dev.gnupg.org/T7136

  • https://gitlab.com/redhat-crypto/libgcrypt/libgcrypt-mirror/-/merge_requests/17

  • Not in scope for libgcrypt security policy, work ongoing to add support in the protocol layer

EPSS

Процентиль: 35%
0.00144
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 1 года назад

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.

CVSS3: 5.9
redhat
больше 1 года назад

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.

CVSS3: 5.9
nvd
больше 1 года назад

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.

suse-cvrf
5 дней назад

Security update for libgcrypt

suse-cvrf
5 дней назад

Security update for libgcrypt

EPSS

Процентиль: 35%
0.00144
Низкий