Vulnerability Details CVE-2018-6829
cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 78.2%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2018-6829
-
cpe:2.3:a:gnupg:libgcrypt:-
-
cpe:2.3:a:gnupg:libgcrypt:0.1.0
-
cpe:2.3:a:gnupg:libgcrypt:0.2.0
-
cpe:2.3:a:gnupg:libgcrypt:0.2.10
-
cpe:2.3:a:gnupg:libgcrypt:0.2.15
-
cpe:2.3:a:gnupg:libgcrypt:0.2.17
-
cpe:2.3:a:gnupg:libgcrypt:0.2.18
-
cpe:2.3:a:gnupg:libgcrypt:0.2.19
-
cpe:2.3:a:gnupg:libgcrypt:0.2.6
-
cpe:2.3:a:gnupg:libgcrypt:0.2.8
-
cpe:2.3:a:gnupg:libgcrypt:0.3.0
-
cpe:2.3:a:gnupg:libgcrypt:0.3.1
-
cpe:2.3:a:gnupg:libgcrypt:0.3.2
-
cpe:2.3:a:gnupg:libgcrypt:0.3.3
-
cpe:2.3:a:gnupg:libgcrypt:0.3.4
-
cpe:2.3:a:gnupg:libgcrypt:0.3.5
-
cpe:2.3:a:gnupg:libgcrypt:0.4.0
-
cpe:2.3:a:gnupg:libgcrypt:0.4.1
-
cpe:2.3:a:gnupg:libgcrypt:0.4.2
-
cpe:2.3:a:gnupg:libgcrypt:0.4.3
-
cpe:2.3:a:gnupg:libgcrypt:0.4.4
-
cpe:2.3:a:gnupg:libgcrypt:0.4.5
-
cpe:2.3:a:gnupg:libgcrypt:0.9.0
-
cpe:2.3:a:gnupg:libgcrypt:0.9.1
-
cpe:2.3:a:gnupg:libgcrypt:0.9.10
-
cpe:2.3:a:gnupg:libgcrypt:0.9.11
-
cpe:2.3:a:gnupg:libgcrypt:0.9.2
-
cpe:2.3:a:gnupg:libgcrypt:0.9.3
-
cpe:2.3:a:gnupg:libgcrypt:0.9.4
-
cpe:2.3:a:gnupg:libgcrypt:0.9.5
-
cpe:2.3:a:gnupg:libgcrypt:0.9.6
-
cpe:2.3:a:gnupg:libgcrypt:0.9.7
-
cpe:2.3:a:gnupg:libgcrypt:0.9.8
-
cpe:2.3:a:gnupg:libgcrypt:0.9.9
-
cpe:2.3:a:gnupg:libgcrypt:1.0.0
-
cpe:2.3:a:gnupg:libgcrypt:1.0.1
-
cpe:2.3:a:gnupg:libgcrypt:1.0.2
-
cpe:2.3:a:gnupg:libgcrypt:1.0.3
-
cpe:2.3:a:gnupg:libgcrypt:1.0.4
-
cpe:2.3:a:gnupg:libgcrypt:1.1.0
-
cpe:2.3:a:gnupg:libgcrypt:1.1.10
-
cpe:2.3:a:gnupg:libgcrypt:1.1.11
-
cpe:2.3:a:gnupg:libgcrypt:1.1.12
-
cpe:2.3:a:gnupg:libgcrypt:1.1.2
-
cpe:2.3:a:gnupg:libgcrypt:1.1.3
-
cpe:2.3:a:gnupg:libgcrypt:1.1.4
-
cpe:2.3:a:gnupg:libgcrypt:1.1.42
-
cpe:2.3:a:gnupg:libgcrypt:1.1.43
-
cpe:2.3:a:gnupg:libgcrypt:1.1.44
-
cpe:2.3:a:gnupg:libgcrypt:1.1.5
-
cpe:2.3:a:gnupg:libgcrypt:1.1.6
-
cpe:2.3:a:gnupg:libgcrypt:1.1.7
-
cpe:2.3:a:gnupg:libgcrypt:1.1.8
-
cpe:2.3:a:gnupg:libgcrypt:1.1.9
-
cpe:2.3:a:gnupg:libgcrypt:1.1.90
-
cpe:2.3:a:gnupg:libgcrypt:1.1.91
-
cpe:2.3:a:gnupg:libgcrypt:1.1.92
-
cpe:2.3:a:gnupg:libgcrypt:1.1.93
-
cpe:2.3:a:gnupg:libgcrypt:1.1.94
-
cpe:2.3:a:gnupg:libgcrypt:1.2.0
-
cpe:2.3:a:gnupg:libgcrypt:1.2.1
-
cpe:2.3:a:gnupg:libgcrypt:1.2.2
-
cpe:2.3:a:gnupg:libgcrypt:1.2.3
-
cpe:2.3:a:gnupg:libgcrypt:1.2.4
-
cpe:2.3:a:gnupg:libgcrypt:1.3.0
-
cpe:2.3:a:gnupg:libgcrypt:1.3.1
-
cpe:2.3:a:gnupg:libgcrypt:1.3.2
-
cpe:2.3:a:gnupg:libgcrypt:1.4.0
-
cpe:2.3:a:gnupg:libgcrypt:1.4.1
-
cpe:2.3:a:gnupg:libgcrypt:1.4.2
-
cpe:2.3:a:gnupg:libgcrypt:1.4.3
-
cpe:2.3:a:gnupg:libgcrypt:1.4.4
-
cpe:2.3:a:gnupg:libgcrypt:1.4.5
-
cpe:2.3:a:gnupg:libgcrypt:1.4.6
-
cpe:2.3:a:gnupg:libgcrypt:1.5.0
-
cpe:2.3:a:gnupg:libgcrypt:1.5.1
-
cpe:2.3:a:gnupg:libgcrypt:1.5.2
-
cpe:2.3:a:gnupg:libgcrypt:1.5.3
-
cpe:2.3:a:gnupg:libgcrypt:1.5.4
-
cpe:2.3:a:gnupg:libgcrypt:1.5.5
-
cpe:2.3:a:gnupg:libgcrypt:1.5.6
-
cpe:2.3:a:gnupg:libgcrypt:1.6.0
-
cpe:2.3:a:gnupg:libgcrypt:1.6.1
-
cpe:2.3:a:gnupg:libgcrypt:1.6.2
-
cpe:2.3:a:gnupg:libgcrypt:1.6.3
-
cpe:2.3:a:gnupg:libgcrypt:1.6.4
-
cpe:2.3:a:gnupg:libgcrypt:1.6.5
-
cpe:2.3:a:gnupg:libgcrypt:1.6.6
-
cpe:2.3:a:gnupg:libgcrypt:1.7.0
-
cpe:2.3:a:gnupg:libgcrypt:1.7.1
-
cpe:2.3:a:gnupg:libgcrypt:1.7.10
-
cpe:2.3:a:gnupg:libgcrypt:1.7.2
-
cpe:2.3:a:gnupg:libgcrypt:1.7.3
-
cpe:2.3:a:gnupg:libgcrypt:1.7.4
-
cpe:2.3:a:gnupg:libgcrypt:1.7.5
-
cpe:2.3:a:gnupg:libgcrypt:1.7.6
-
cpe:2.3:a:gnupg:libgcrypt:1.7.7
-
cpe:2.3:a:gnupg:libgcrypt:1.7.8
-
cpe:2.3:a:gnupg:libgcrypt:1.7.9
-
cpe:2.3:a:gnupg:libgcrypt:1.8.0
-
cpe:2.3:a:gnupg:libgcrypt:1.8.1
-
cpe:2.3:a:gnupg:libgcrypt:1.8.2