Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-9564

Опубликовано: 07 июл. 2022
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2022-9564: libgcrypt security update (IMPORTANT)

[ 1.8.5-7_fips]

  • Add API to provide hash calculation in RSA/DSA/ECDSA signature operations [Orabug: 33081130]
  • Change Epoch from 1 to 10

[1.8.5-7]

  • Fix CVE-2021-33560 (#2018525)

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

libgcrypt

1.8.5-7.el8_6_fips

libgcrypt-devel

1.8.5-7.el8_6_fips

Oracle Linux x86_64

libgcrypt

1.8.5-7.el8_6_fips

libgcrypt-devel

1.8.5-7.el8_6_fips

Связанные CVE

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 4 года назад

The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.

CVSS3: 5.9
redhat
почти 4 года назад

The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.

CVSS3: 5.9
nvd
почти 4 года назад

The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.

CVSS3: 5.9
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 5.9
debian
почти 4 года назад

The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext ...