Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-9526

Опубликовано: 01 июн. 2017
Источник: redhat
CVSS3: 5.9

Описание

In Libgcrypt before 1.7.7, an attacker who learns the EdDSA session key (from side-channel observation during the signing process) can easily recover the long-term secret key. 1.7.7 makes a cipher/ecc-eddsa.c change to store this session key in secure memory, to ensure that constant-time point operations are used in the MPI library.

Отчет

This issue did not affect the versions of libgcrypt as shipped with Red Hat Enterprise Linux 5, 6 and 7 as they did not include support for EdDSA cipher.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libgcryptNot affected
Red Hat Enterprise Linux 6libgcryptNot affected
Red Hat Enterprise Linux 7libgcryptNot affected
Red Hat Enterprise Virtualization 3mingw-virt-viewerNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-385
https://bugzilla.redhat.com/show_bug.cgi?id=1459887libgcrypt: Possible timing attack on EdDSA session key

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 9 лет назад

In Libgcrypt before 1.7.7, an attacker who learns the EdDSA session key (from side-channel observation during the signing process) can easily recover the long-term secret key. 1.7.7 makes a cipher/ecc-eddsa.c change to store this session key in secure memory, to ensure that constant-time point operations are used in the MPI library.

CVSS3: 5.9
nvd
больше 9 лет назад

In Libgcrypt before 1.7.7, an attacker who learns the EdDSA session key (from side-channel observation during the signing process) can easily recover the long-term secret key. 1.7.7 makes a cipher/ecc-eddsa.c change to store this session key in secure memory, to ensure that constant-time point operations are used in the MPI library.

CVSS3: 5.9
debian
больше 9 лет назад

In Libgcrypt before 1.7.7, an attacker who learns the EdDSA session ke ...

suse-cvrf
около 9 лет назад

Security update for libgcrypt

suse-cvrf
больше 9 лет назад

Security update for libgcrypt

5.9 Medium

CVSS3