ALT-PU-2020-1687-1
Closed vulnerabilities
BDU:2020-01727
Уязвимость криптографической библиотеки Python ECDSA, связанная с недостаточной обработкой исключительных состояний, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-12904
In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an assembly-language implementation is unavailable.) NOTE: the vendor's position is that the issue report cannot be validated because there is no description of an attack
- openSUSE-SU-2019:1792
- openSUSE-SU-2019:1792
- https://dev.gnupg.org/T4541
- https://dev.gnupg.org/T4541
- https://github.com/gpg/libgcrypt/commit/a4c561aab1014c3630bc88faf6f5246fee16b020
- https://github.com/gpg/libgcrypt/commit/a4c561aab1014c3630bc88faf6f5246fee16b020
- https://github.com/gpg/libgcrypt/commit/daedbbb5541cd8ecda1459d3b843ea4d92788762
- https://github.com/gpg/libgcrypt/commit/daedbbb5541cd8ecda1459d3b843ea4d92788762
- [mina-dev] 20210225 [jira] [Created] (FTPSERVER-500) Security vulnerability in common/lib/log4j-1.2.17.jar
- [mina-dev] 20210225 [jira] [Created] (FTPSERVER-500) Security vulnerability in common/lib/log4j-1.2.17.jar
Modified: 2024-11-21
CVE-2019-13627
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.
- openSUSE-SU-2019:2161
- openSUSE-SU-2019:2161
- openSUSE-SU-2020:0022
- openSUSE-SU-2020:0022
- [oss-security] 20191002 Minerva: ECDSA key recovery from bit-length leakage
- [oss-security] 20191002 Minerva: ECDSA key recovery from bit-length leakage
- https://github.com/gpg/libgcrypt/releases/tag/libgcrypt-1.8.5
- https://github.com/gpg/libgcrypt/releases/tag/libgcrypt-1.8.5
- [debian-lts-announce] 20190924 [SECURITY] [DLA 1931-1] libgcrypt20 security update
- [debian-lts-announce] 20190924 [SECURITY] [DLA 1931-1] libgcrypt20 security update
- [debian-lts-announce] 20200101 [SECURITY] [DLA 1931-2] libgcrypt20 regression update
- [debian-lts-announce] 20200101 [SECURITY] [DLA 1931-2] libgcrypt20 regression update
- https://minerva.crocs.fi.muni.cz/
- https://minerva.crocs.fi.muni.cz/
- GLSA-202003-32
- GLSA-202003-32
- https://security-tracker.debian.org/tracker/CVE-2019-13627
- https://security-tracker.debian.org/tracker/CVE-2019-13627
- USN-4236-1
- USN-4236-1
- USN-4236-2
- USN-4236-2
- USN-4236-3
- USN-4236-3