Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2014-10-10T01:00:00

Updated: 2024-08-06T11:41:47.780Z

Reserved: 2014-08-15T00:00:00

Link: CVE-2014-5270

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2014-10-10T01:55:10.383

Modified: 2024-11-21T02:11:44.490

Link: CVE-2014-5270

cve-icon Redhat

Severity : Moderate

Publid Date: 2014-08-08T00:00:00Z

Links: CVE-2014-5270 - Bugzilla