PT-2017-3251 · Gnu+4 · Libgcrypt+4

Christine Van Vredendaal

+7

·

Publicado

2017-06-29

·

Atualizado

2024-06-15

·

CVE-2017-7526

CVSS v3.1

6.8

Média

VetorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions libgcrypt versions prior to 1.7.8
Description The issue is related to a cache side-channel attack that can lead to a complete break of RSA-1024 and potentially RSA-2048 with increased computation. This attack requires the ability to run arbitrary software on the hardware where the private RSA key is used, allowing a local attacker to compromise data confidentiality by fully recovering the RSA key using the left-to-right method for computing the sliding-window expansion.
Recommendations For libgcrypt versions prior to 1.7.8, update to version 1.7.8 or later to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1818
ALT-PU-2017-1869
ALT-PU-2017-2769
ALT-PU-2018-2426
AZL-41702
BDU:2018-00007
CVE-2017-7526
DLA-1015-1
DLA-1080-1
DSA-3901-1
DSA-3960-1
MGASA-2017-0213
MGASA-2017-0235
OPENSUSE-SU-2024:10941-1
SUSE-SU-2017:1793-1
SUSE-SU-2017:1794-1
SUSE-SU-2017:1866-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
SUSE-SU-2017_1793-1
SUSE-SU-2017_1794-1
SUSE-SU-2017_1866-1
USN-3347-1
USN-3347-2
USN-3733-1
USN-3733-2

Produtos afetados

Alt Linux
Astra Linux
Suse
Ubuntu
Libgcrypt