Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-0837

Опубликовано: 27 фев. 2015
Источник: redhat
CVSS2: 1.2

Описание

The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."

Отчет

Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw in the libgcrypt and gnupg2 packages. The attack leading to this flaw, is difficult to conduct in practice especially for cross-vm environments, mainly because the attacker needs to run their timing attack script at the exact same time decryption runs on the victim machine. Also this is essentially a chosen ciphertext attack because the attacker provides the ciphertext which the victim needs to be decrypt. Such actions only work when there is sufficient social engineer involved.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gnupgWill not fix
Red Hat Enterprise Linux 5gnupg2Will not fix
Red Hat Enterprise Linux 5libgcryptWill not fix
Red Hat Enterprise Linux 6gnupg2Will not fix
Red Hat Enterprise Linux 6libgcryptWill not fix
Red Hat Enterprise Linux 7gnupg2Will not fix
Red Hat Enterprise Linux 7libgcryptWill not fix
Red Hat Enterprise Virtualization 3mingw-virt-viewerFix deferred

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1198147libgcrypt: last-level cache side-channel attack

1.2 Low

CVSS2

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 6 лет назад

The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."

CVSS3: 5.9
nvd
около 6 лет назад

The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."

CVSS3: 5.9
debian
около 6 лет назад

The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.1 ...

suse-cvrf
больше 10 лет назад

Security update for libgcrypt

CVSS3: 5.9
github
больше 3 лет назад

The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."

1.2 Low

CVSS2