Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:5311

Опубликовано: 28 июн. 2022
Источник: rocky
Оценка: Moderate

Описание

Moderate: libgcrypt security update

The libgcrypt library provides general-purpose implementations of various cryptographic algorithms.

Security Fix(es):

  • libgcrypt: ElGamal implementation allows plaintext recovery (CVE-2021-40528)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
libgcryptx86_647.el8_6libgcrypt-1.8.5-7.el8_6.x86_64.rpm
libgcrypt-develx86_647.el8_6libgcrypt-devel-1.8.5-7.el8_6.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 4 года назад

The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.

CVSS3: 5.9
redhat
почти 4 года назад

The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.

CVSS3: 5.9
nvd
почти 4 года назад

The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.

CVSS3: 5.9
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 5.9
debian
почти 4 года назад

The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext ...