PT-2013-1197 · Gnu+2 · Gnupg+2

Adi Shamir

+2

·

Published

2013-12-20

·

Updated

2017-08-29

·

CVE-2013-4576

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions GnuPG versions 1.4.5 through 1.4.15
Description The issue allows attackers to extract RSA keys via a chosen-ciphertext attack and acoustic cryptanalysis during decryption. This can be exploited remotely and may lead to a violation of the confidentiality and integrity of protected information. The vulnerability is related to the generation of RSA keys using sequences of introductions with certain patterns, which introduces a side channel.
Recommendations For GnuPG versions 1.4.5 through 1.4.15, update to version 1.4.16 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information and physical devices to minimize the risk of exploitation. Avoid using the vulnerable GnuPG versions for sensitive operations until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2013-1314
BDU:2015-07748
BDU:2015-07749
BDU:2015-09067
BDU:2015-09068
CVE-2013-4576
DSA-2821-1
MGASA-2013-0382
RHSA-2014:0016
RHSA-2014_0016

Affected Products

Alt Linux
Gnupg
Red Hat