It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.
2019-09-25T15:15:11.877
2024-11-21T04:25:23.730
Modified
CVSSv3.1: 6.3 (MEDIUM)
AV:L/AC:H/Au:N/C:P/I:P/A:N
1.9
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | canonical | ubuntu_linux | 12.04 | Yes |
Operating System | canonical | ubuntu_linux | 14.04 | Yes |
Operating System | canonical | ubuntu_linux | 16.04 | Yes |
Operating System | canonical | ubuntu_linux | 18.04 | Yes |
Operating System | canonical | ubuntu_linux | 19.04 | Yes |
Operating System | canonical | ubuntu_linux | 19.10 | Yes |
Operating System | opensuse | leap | 15.0 | Yes |
Operating System | opensuse | leap | 15.1 | Yes |
Application | libgcrypt20_project | libgcrypt20 | 1.6.3-2\+deb8u4 | Yes |
Operating System | debian | debian_linux | 8.0 | No |
Application | libgcrypt20_project | libgcrypt20 | 1.7.6-2\+deb9u3 | Yes |
Operating System | debian | debian_linux | 9.0 | No |
Application | libgcrypt20_project | libgcrypt20 | 1.8.4-5 | Yes |
Operating System | debian | debian_linux | 10.0 | No |