Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-2236

Опубликовано: 06 мар. 2024
Источник: redhat
CVSS3: 5.9

Описание

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.

Отчет

An attacker would have to be able to send a large number of trial messages to achieve successful decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OAEP, and RSASVE.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libgcryptNot affected
Red Hat Enterprise Linux 6libgcryptOut of support scope
Red Hat Enterprise Linux 7libgcryptAffected
Red Hat Enterprise Linux 8libgcryptAffected
Red Hat Enterprise Linux 9libgcryptFixedRHSA-2024:940412.11.2024
Red Hat Enterprise Linux 9libgcryptFixedRHSA-2024:940412.11.2024
Red Hat Enterprise Linux 9.2 Extended Update SupportlibgcryptFixedRHSA-2025:353402.04.2025
Red Hat Enterprise Linux 9.4 Extended Update SupportlibgcryptFixedRHSA-2025:353002.04.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-385
https://bugzilla.redhat.com/show_bug.cgi?id=2245218libgcrypt: vulnerable to Marvin Attack

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 2 лет назад

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.

CVSS3: 5.9
nvd
около 2 лет назад

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.

CVSS3: 5.9
debian
около 2 лет назад

A timing-based side-channel flaw was found in libgcrypt's RSA implemen ...

suse-cvrf
8 месяцев назад

Security update for libgcrypt

suse-cvrf
8 месяцев назад

Security update for libgcrypt

5.9 Medium

CVSS3