Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-33560

Опубликовано: 08 июн. 2021
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.

РелизСтатусПримечание
bionic

released

1.8.1-4ubuntu1.3
devel

released

1.8.7-5ubuntu2
esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

1.8.1-4ubuntu1.3
esm-infra/focal

not-affected

1.8.5-5ubuntu1.1
esm-infra/xenial

released

1.6.5-2ubuntu0.6+esm1
fips-preview/jammy

released

1.8.7-5ubuntu2
fips-updates/bionic

released

1.8.1-4ubuntu1.fips.3
fips-updates/focal

released

1.8.5-5ubuntu1.fips.1.1
fips-updates/jammy

released

1.8.7-5ubuntu2

Показывать по

EPSS

Процентиль: 66%
0.0053
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
около 4 лет назад

Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.

CVSS3: 7.5
nvd
около 4 лет назад

Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.

CVSS3: 7.5
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 7.5
debian
около 4 лет назад

Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encry ...

suse-cvrf
около 4 лет назад

Security update for libgcrypt

EPSS

Процентиль: 66%
0.0053
Низкий

5 Medium

CVSS2

7.5 High

CVSS3