VYPR
Unrated severityNVD Advisory· Published Dec 20, 2013· Updated Apr 29, 2026

CVE-2013-4576

CVE-2013-4576

Description

GnuPG 1.x before 1.4.16 generates RSA keys using sequences of introductions with certain patterns that introduce a side channel, which allows physically proximate attackers to extract RSA keys via a chosen-ciphertext attack and acoustic cryptanalysis during decryption. NOTE: applications are not typically expected to protect themselves from acoustic side-channel attacks, since this is arguably the responsibility of the physical device. Accordingly, issues of this type would not normally receive a CVE identifier. However, for this issue, the developer has specified a security policy in which GnuPG should offer side-channel resistance, and developer-specified security-policy violations are within the scope of CVE.

Affected products

43
  • Gnupg/Gnupg43 versions
    cpe:2.3:a:gnupg:gnupg:*:*:*:*:*:*:*:*+ 42 more
    • cpe:2.3:a:gnupg:gnupg:*:*:*:*:*:*:*:*range: <=1.4.15
    • cpe:2.3:a:gnupg:gnupg:1.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.0.4:-:win32:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.0.5:-:win32:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.2.1:windows:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.2.4:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.2.6:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.2.7:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.3.3:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.3.4:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.3.6:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.3.90:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.3.91:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.3.92:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.3.93:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.4.10:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.4.11:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.4.12:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.4.13:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.4.14:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.4.2:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.4.3:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.4.4:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.4.5:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.4.6:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:gnupg:1.4.8:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

12

News mentions

0

No linked articles in our index yet.