Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-0837

Опубликовано: 29 нояб. 2019
Источник: nvd
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gnupg:gnupg:*:*:*:*:*:*:*:*
Версия до 1.4.19 (исключая)
cpe:2.3:a:gnupg:libgcrypt:*:*:*:*:*:*:*:*
Версия до 1.6.3 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 71%
0.00677
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-203

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 6 лет назад

The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."

redhat
почти 11 лет назад

The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."

CVSS3: 5.9
debian
около 6 лет назад

The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.1 ...

suse-cvrf
больше 10 лет назад

Security update for libgcrypt

CVSS3: 5.9
github
больше 3 лет назад

The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."

EPSS

Процентиль: 71%
0.00677
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-203