PT-2013-1070 · Gnu+3 · Libgcrypt+4

Katrina Falkner

+1

·

Published

2013-08-03

·

Updated

2024-06-15

·

CVE-2013-4242

CVSS v2.0

1.9

Low

VectorAV:L/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions libgcrypt versions 1.4.4 through 1.4.5 libgcrypt-devel versions 1.4.4 through 1.4.5 libgcrypt-debuginfo versions 1.4.4 through 1.4.5 GnuPG versions prior to 1.4.14 Libgcrypt versions prior to 1.5.3
Description The issue allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache. This can lead to a violation of confidentiality of protected information. The exploitation of the issue can be carried out locally.
Recommendations For libgcrypt versions 1.4.4 through 1.4.5, consider updating to a version prior to the vulnerability, such as libgcrypt version 1.5.3 or later. For libgcrypt-devel versions 1.4.4 through 1.4.5, consider updating to a version prior to the vulnerability, such as libgcrypt version 1.5.3 or later. For libgcrypt-debuginfo versions 1.4.4 through 1.4.5, consider updating to a version prior to the vulnerability, such as libgcrypt version 1.5.3 or later. For GnuPG versions prior to 1.4.14, consider updating to GnuPG version 1.4.14 or later. For Libgcrypt versions prior to 1.5.3, consider updating to Libgcrypt version 1.5.3 or later. As a temporary workaround, consider restricting access to sensitive information until a patch is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02032
BDU:2015-06685
BDU:2015-06686
BDU:2015-06687
BDU:2015-06688
BDU:2015-06689
BDU:2015-06690
BDU:2015-09029
BDU:2015-09030
BDU:2015-09031
BDU:2015-09032
BDU:2015-09033
BDU:2015-09034
CESA-2013_1457
CVE-2013-4242
DSA-2730-1
DSA-2731-1
MGASA-2013-0239
OPENSUSE-SU-2024:10037-1
RHSA-2013:1457
RHSA-2013:1458
RHSA-2013_1457
RHSA-2013_1458
SUSE-SU-2013_1352-1
SUSE-SU-2014_0704-1

Affected Products

Centos
Gnupg
Red Hat
Suse
Libgcrypt