rpm package
suse/libgcrypt&distro=SUSE Linux Enterprise Server 12 SP3-LTSS
pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSS
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-33560 | — | < 1.6.1-16.77.1 | 1.6.1-16.77.1 | Jun 8, 2021 | Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP. | ||
| CVE-2019-13627 | — | < 1.6.1-16.68.1 | 1.6.1-16.68.1 | Sep 25, 2019 | It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7. |
- CVE-2021-33560Jun 8, 2021affected < 1.6.1-16.77.1fixed 1.6.1-16.77.1
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.
- CVE-2019-13627Sep 25, 2019affected < 1.6.1-16.68.1fixed 1.6.1-16.68.1
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.