PT-2014-5408 · Gnu+3 · Libgcrypt+4

Daniel Genkin

·

Published

2014-12-31

·

Updated

2024-06-15

·

CVE-2014-3591

CVSS v3.1

4.2

Medium

VectorAV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Libgcrypt versions prior to 1.6.3 GnuPG versions prior to 1.4.19
Description The issue concerns the lack of ciphertext blinding for Elgamal decryption, allowing physically proximate attackers to obtain the server's private key. This is achieved by determining factors using crafted ciphertext and analyzing the fluctuations in the electromagnetic field during multiplication.
Recommendations For Libgcrypt versions prior to 1.6.3, update to version 1.6.3 or later to resolve the issue. For GnuPG versions prior to 1.4.19, update to version 1.4.19 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1541
ALT-PU-2015-2052
AZL-41815
CVE-2014-3591
DLA-175-1
DLA-190-1
DSA-3184-1
DSA-3185-1
MGASA-2015-0104
OPENSUSE-SU-2024:10037-1
SUSE-SU-2015:1179-1
SUSE-SU-2015:1626-1
SUSE-SU-2015_1179-1
SUSE-SU-2015_1626-1
USN-2554-1
USN-2555-1

Affected Products

Alt Linux
Gnupg
Libgcrypt
Suse
Ubuntu