Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-0379

Опубликовано: 27 авг. 2017
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.c.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libgcryptNot affected
Red Hat Enterprise Linux 6libgcryptNot affected
Red Hat Enterprise Linux 7libgcryptNot affected
Red Hat Enterprise Virtualization 3mingw-virt-viewerNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1485921libgcrypt: Missing input validation for X25519 curve

EPSS

Процентиль: 83%
0.01856
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.c.

CVSS3: 7.5
nvd
больше 8 лет назад

Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.c.

CVSS3: 7.5
debian
больше 8 лет назад

Libgcrypt before 1.8.1 does not properly consider Curve25519 side-chan ...

CVSS3: 7.5
github
больше 3 лет назад

Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.c.

EPSS

Процентиль: 83%
0.01856
Низкий

4.4 Medium

CVSS3