Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-13627

Опубликовано: 02 окт. 2019
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.

A timing attack was found in the way ECCDSA was implemented in libgcrypt. A man-in-the-middle attacker could use this attack during signature generation to recover the private key. This attack is only feasible when the attacker is local to the machine where the signature is being generated. Attacks over the network or via the internet are not feasible.

Отчет

The versions of libgcrypt shipped with Red Hat Enterprise Linux 5, 6 and 7 do not support ECC, therefore they are not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libgcryptNot affected
Red Hat Enterprise Linux 6libgcryptNot affected
Red Hat Enterprise Linux 7libgcryptNot affected
Red Hat Enterprise Linux 8libgcryptFixedRHSA-2020:448204.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-362
https://bugzilla.redhat.com/show_bug.cgi?id=1764018libgcrypt: ECDSA timing attack allowing private key leak

EPSS

Процентиль: 12%
0.00039
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
ubuntu
больше 6 лет назад

It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.

CVSS3: 6.3
nvd
больше 6 лет назад

It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.

CVSS3: 6.3
debian
больше 6 лет назад

It was discovered that there was a ECDSA timing attack in the libgcryp ...

suse-cvrf
около 6 лет назад

Security update for libgcrypt

suse-cvrf
больше 6 лет назад

Security update for libgcrypt

EPSS

Процентиль: 12%
0.00039
Низкий

6.3 Medium

CVSS3