Vulnerabilities
Vulnerable Software
Gnupg:  >> Libgcrypt  >> 0.2.18  Security Vulnerabilities
Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations.
CVSS Score
2.0
EPSS Score
0.001
Published
2016-04-19
Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576.
CVSS Score
2.1
EPSS Score
0.001
Published
2014-10-10
GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.
CVSS Score
1.9
EPSS Score
0.001
Published
2013-08-19


Contact Us

Shodan ® - All rights reserved