Medium severity5.9NVD Advisory· Published Nov 29, 2019· Updated Jun 17, 2026
CVE-2015-0837
CVE-2015-0837
Description
The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
22- Range: <1.6.3
- osv-coords14 versionspkg:rpm/opensuse/libgcrypt&distro=openSUSE%20Tumbleweedpkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP3pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP4pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATApkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Server%2012pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP3pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP3pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012
< 1.7.3-1.3+ 13 more
- (no CPE)range: < 1.7.3-1.3
- (no CPE)range: < 1.5.0-0.19.1
- (no CPE)range: < 1.5.0-0.19.1
- (no CPE)range: < 1.6.1-16.1
- (no CPE)range: < 1.5.0-0.19.1
- (no CPE)range: < 1.5.0-0.19.1
- (no CPE)range: < 1.5.0-0.19.1
- (no CPE)range: < 1.6.1-16.1
- (no CPE)range: < 1.5.0-0.19.1
- (no CPE)range: < 1.5.0-0.19.1
- (no CPE)range: < 1.6.1-16.1
- (no CPE)range: < 1.5.0-0.19.1
- (no CPE)range: < 1.5.0-0.19.1
- (no CPE)range: < 1.6.1-16.1
- GNU/GnuPGv5Range: before 1.4.19
- GNU/Libgcryptv5Range: before 1.6.3
Patches
Vulnerability mechanics
References
5- www.debian.org/security/2015/dsa-3184nvdThird Party Advisory
- www.debian.org/security/2015/dsa-3185nvdThird Party Advisory
- ieeexplore.ieee.org/document/7163050nvdThird Party Advisory
- lists.gnupg.org/pipermail/gnupg-announce/2015q1/000363.htmlnvdMailing ListVendor Advisory
- lists.gnupg.org/pipermail/gnupg-announce/2015q1/000364.htmlnvdMailing ListVendor Advisory
News mentions
0No linked articles in our index yet.