ECDSA Timing Attack Vulnerability in libgcrypt20 by GnuPG
CVE-2019-13627

6.3MEDIUM

Key Information:

Vendor
Canonical
Vendor
CVE Published:
25 September 2019

Summary

A vulnerability was identified in the libgcrypt20 cryptographic library where an ECDSA timing attack could potentially allow attackers to recover private keys. This vulnerability affects specific versions of the library, and it's crucial for users to update to the fixed versions to mitigate the risk. Patching to versions 1.8.5-2 or 1.6.3-2+deb8u7 is highly advised to ensure security and protect sensitive data.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.