It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1931-1 | libgcrypt20 security update |
Debian DLA |
DLA-1931-2 | libgcrypt20 regression update |
EUVD |
EUVD-2019-5059 | It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7. |
Ubuntu USN |
USN-4236-1 | Libgcrypt vulnerability |
Ubuntu USN |
USN-4236-2 | Libgcrypt vulnerability |
Ubuntu USN |
USN-4236-3 | Libgcrypt vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T23:57:39.524Z
Reserved: 2019-07-17T00:00:00
Link: CVE-2019-13627
No data.
Status : Modified
Published: 2019-09-25T15:15:11.877
Modified: 2024-11-21T04:25:23.730
Link: CVE-2019-13627
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN