Medium severity4.2NVD Advisory· Published Nov 29, 2019· Updated Jun 17, 2026
CVE-2014-3591
CVE-2014-3591
Description
Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using crafted ciphertext and the fluctuations in the electromagnetic field during multiplication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
22- Range: <1.6.3
- osv-coords14 versionspkg:rpm/opensuse/libgcrypt&distro=openSUSE%20Tumbleweedpkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP3pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP4pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATApkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Server%2012pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP3pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP3pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012
< 1.7.3-1.3+ 13 more
- (no CPE)range: < 1.7.3-1.3
- (no CPE)range: < 1.5.0-0.19.1
- (no CPE)range: < 1.5.0-0.19.1
- (no CPE)range: < 1.6.1-13.1
- (no CPE)range: < 1.5.0-0.19.1
- (no CPE)range: < 1.5.0-0.19.1
- (no CPE)range: < 1.5.0-0.19.1
- (no CPE)range: < 1.6.1-13.1
- (no CPE)range: < 1.5.0-0.19.1
- (no CPE)range: < 1.5.0-0.19.1
- (no CPE)range: < 1.6.1-13.1
- (no CPE)range: < 1.5.0-0.19.1
- (no CPE)range: < 1.5.0-0.19.1
- (no CPE)range: < 1.6.1-13.1
- GNU/GnuPGv5Range: before 1.4.19
- GNU/Libgcryptv5Range: before 1.6.3
Patches
Vulnerability mechanics
References
5- lists.gnupg.org/pipermail/gnupg-announce/2015q1/000363.htmlnvdPatchRelease NotesVendor Advisory
- lists.gnupg.org/pipermail/gnupg-announce/2015q1/000364.htmlnvdPatchVendor Advisory
- www.cs.tau.ac.il/~tromer/radioexp/nvdThird Party Advisory
- www.debian.org/security/2015/dsa-3184nvdThird Party Advisory
- www.debian.org/security/2015/dsa-3185nvdThird Party Advisory
News mentions
0No linked articles in our index yet.