PT-2014-5408 · Gnu+3 · Libgcrypt+4

Daniel Genkin

·

Publicado

2014-12-31

·

Atualizado

2024-06-15

·

CVE-2014-3591

CVSS v3.1

4.2

Média

VetorAV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Libgcrypt versions prior to 1.6.3 GnuPG versions prior to 1.4.19
Description The issue concerns the lack of ciphertext blinding for Elgamal decryption, allowing physically proximate attackers to obtain the server's private key. This is achieved by determining factors using crafted ciphertext and analyzing the fluctuations in the electromagnetic field during multiplication.
Recommendations For Libgcrypt versions prior to 1.6.3, update to version 1.6.3 or later to resolve the issue. For GnuPG versions prior to 1.4.19, update to version 1.4.19 or later to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1541
ALT-PU-2015-2052
AZL-41815
CVE-2014-3591
DLA-175-1
DLA-190-1
DSA-3184-1
DSA-3185-1
MGASA-2015-0104
OPENSUSE-SU-2024:10037-1
SUSE-SU-2015:1179-1
SUSE-SU-2015:1626-1
SUSE-SU-2015_1179-1
SUSE-SU-2015_1626-1
USN-2554-1
USN-2555-1

Produtos afetados

Alt Linux
Gnupg
Libgcrypt
Suse
Ubuntu