Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-40528

Опубликовано: 20 июл. 2021
Источник: redhat
CVSS3: 5.9

Описание

The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.

A flaw was found in libgcrypt's ElGamal implementation, where it allows plain text recovery. During the interaction between two cryptographic libraries, a certain combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP. The highest threat from this vulnerability is to confidentiality.

Отчет

Please note that there was a mixup between this CVE and CVE-2021-33560. At this time, both CVEs should be assumed to refer to the same issue. More information will be provided in the near future. See the first link in External References for more information.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libgcryptOut of support scope
Red Hat Enterprise Linux 7libgcryptOut of support scope
Red Hat Enterprise Linux 9libgcryptNot affected
Red Hat Enterprise Linux 8libgcryptFixedRHSA-2022:531130.06.2022

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2002816libgcrypt: ElGamal implementation allows plaintext recovery

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 4 года назад

The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.

CVSS3: 5.9
nvd
почти 4 года назад

The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.

CVSS3: 5.9
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 5.9
debian
почти 4 года назад

The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext ...

redos
больше 3 лет назад

Уязвимость криптографической библиотеки Libgcrypt

5.9 Medium

CVSS3