All errata/sisyphus/ALT-PU-2019-2588-1
ALT-PU-2019-2588-1

Package update libgcrypt in branch sisyphus

Version1.8.5-alt1
Published2019-08-30
Max severityMEDIUM
Severity:

Closed issues (3)

BDU:2020-01727
LOW3.6

Уязвимость криптографической библиотеки Python ECDSA, связанная с недостаточной обработкой исключительных состояний, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2020-04-23Modified: 2024-04-27
CVSS 3.xLOW 3.6
CVSS:3.x/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS 2.0LOW 2.6
CVSS:2.0/AV:L/AC:H/Au:N/C:P/I:P/A:N
References
CVE-2019-12904
MEDIUM5.9

In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an assembly-language implementation is unavailable.) NOTE: the vendor's position is that the issue report cannot be validated because there is no description of an attack

Published: 2019-06-20Modified: 2024-11-21
CVSS 2.0MEDIUM 4.3
CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:N/A:N
CVSS 3.xMEDIUM 5.9
CVSS:3.x/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE-2019-13627
MEDIUM6.3

It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.

Published: 2019-09-25Modified: 2024-11-21
CVSS 2.0LOW 2.6
CVSS:2.0/AV:L/AC:H/Au:N/C:P/I:P/A:N
CVSS 3.xMEDIUM 6.3
CVSS:3.x/CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N