PT-2019-5078 · Debian+7 · Libgcrypt20+7
Publicado
2019-08-30
·
Atualizado
2024-06-15
·
CVE-2019-13627
CVSS v3.1
6.3
Média
| Vetor | AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
libgcrypt20 versions 1.6.3-2+deb8u4 through 1.8.4-5
Description
The issue is related to an ECDSA timing attack in the libgcrypt20 cryptographic library. It may also be associated with a situation where concurrent execution with shared resources and improper synchronization can lead to exploitation, potentially causing a denial of service.
Recommendations
For versions 1.6.3-2+deb8u4 through 1.7.6-2+deb9u3, update to version 1.6.3-2+deb8u7 or later.
For versions 1.8.4-5, update to version 1.8.5-2 or later.
Correção
Side Channel Attack
Race Condition
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Astra Linux
Centos
Red Hat
Rocky Linux
Suse
Ubuntu
Libgcrypt20