Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Itamar Pipman

#52242de 53,634
4.1CVSS total
Vulnerabilidades · 2
Baixa
2
PT-2015-7557
2.0
2015-12-31
Gnu · Libgcrypt · CVE-2015-7511
**Name of the Vulnerable Software and Affected Versions** Libgcrypt versions prior to 1.6.5 **Description** The issue makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations due to improper elliptic-point curve multiplication during decryption. **Recommendations** For versions prior to 1.6.5, update to version 1.6.5 or later to resolve the issue.
PT-2014-1931
2.1
2014-08-11
Gnu · Libgcrypt · CVE-2014-5270
**Name of the Vulnerable Software and Affected Versions** libgcrypt versions prior to 1.5.4 **Description** The issue concerns the improper performance of ciphertext normalization and ciphertext randomization in libgcrypt, which can be exploited by physically proximate attackers to conduct key-extraction attacks. This is achieved by collecting voltage data from exposed metal, representing a different attack vector. The vulnerability can lead to a breach of confidentiality of protected information and can be exploited locally. **Recommendations** For libgcrypt versions prior to 1.5.4, update to version 1.5.4 or later to resolve the issue.