PT-2017-3251 · Gnu+4 · Libgcrypt+4

Christine Van Vredendaal

+7

·

Published

2017-06-29

·

Updated

2024-06-15

·

CVE-2017-7526

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions libgcrypt versions prior to 1.7.8
Description The issue is related to a cache side-channel attack that can lead to a complete break of RSA-1024 and potentially RSA-2048 with increased computation. This attack requires the ability to run arbitrary software on the hardware where the private RSA key is used, allowing a local attacker to compromise data confidentiality by fully recovering the RSA key using the left-to-right method for computing the sliding-window expansion.
Recommendations For libgcrypt versions prior to 1.7.8, update to version 1.7.8 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1818
ALT-PU-2017-1869
ALT-PU-2017-2769
ALT-PU-2018-2426
AZL-41702
BDU:2018-00007
CVE-2017-7526
DLA-1015-1
DLA-1080-1
DSA-3901-1
DSA-3960-1
MGASA-2017-0213
MGASA-2017-0235
OPENSUSE-SU-2024:10941-1
SUSE-SU-2017:1793-1
SUSE-SU-2017:1794-1
SUSE-SU-2017:1866-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
SUSE-SU-2017_1793-1
SUSE-SU-2017_1794-1
SUSE-SU-2017_1866-1
USN-3347-1
USN-3347-2
USN-3733-1
USN-3733-2

Affected Products

Alt Linux
Astra Linux
Suse
Ubuntu
Libgcrypt