PT-2019-5078 · Debian+7 · Libgcrypt20+7
Published
2019-08-30
·
Updated
2024-06-15
·
CVE-2019-13627
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
libgcrypt20 versions 1.6.3-2+deb8u4 through 1.8.4-5
Description
The issue is related to an ECDSA timing attack in the libgcrypt20 cryptographic library. It may also be associated with a situation where concurrent execution with shared resources and improper synchronization can lead to exploitation, potentially causing a denial of service.
Recommendations
For versions 1.6.3-2+deb8u4 through 1.7.6-2+deb9u3, update to version 1.6.3-2+deb8u7 or later.
For versions 1.8.4-5, update to version 1.8.5-2 or later.
Fix
Side Channel Attack
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Centos
Red Hat
Rocky Linux
Suse
Ubuntu
Libgcrypt20