PT-2019-5078 · Debian+7 · Libgcrypt20+7

Published

2019-08-30

·

Updated

2024-06-15

·

CVE-2019-13627

CVSS v3.1

6.3

Medium

VectorAV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions libgcrypt20 versions 1.6.3-2+deb8u4 through 1.8.4-5
Description The issue is related to an ECDSA timing attack in the libgcrypt20 cryptographic library. It may also be associated with a situation where concurrent execution with shared resources and improper synchronization can lead to exploitation, potentially causing a denial of service.
Recommendations For versions 1.6.3-2+deb8u4 through 1.7.6-2+deb9u3, update to version 1.6.3-2+deb8u7 or later. For versions 1.8.4-5, update to version 1.8.5-2 or later.

Fix

Side Channel Attack

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2588
ALT-PU-2020-1687
AZL-41066
BDU:2020-01727
CESA-2020_4482
CVE-2019-13627
DLA-1931-1
DLA-1931-2
MGASA-2019-0256
OPENSUSE-SU-2019:2161-1
OPENSUSE-SU-2019_2161-1
OPENSUSE-SU-2020:0022-1
OPENSUSE-SU-2020_0022-1
OPENSUSE-SU-2024:10941-1
RHSA-2020:4482
RHSA-2020_4482
RLSA-2020:4482
SUSE-SU-2019:2349-1
SUSE-SU-2019:2510-1
SUSE-SU-2019:3392-1
SUSE-SU-2019_2349-1
SUSE-SU-2019_2510-1
SUSE-SU-2019_3392-1
USN-4236-1
USN-4236-2
USN-4236-3

Affected Products

Alt Linux
Astra Linux
Centos
Red Hat
Rocky Linux
Suse
Ubuntu
Libgcrypt20