CVE-2014-3591
Summary
| CVE | CVE-2014-3591 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-29 22:15:00 UTC |
| Updated | 2019-12-05 18:06:00 UTC |
| Description | Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using crafted ciphertext and the fluctuations in the electromagnetic field during multiplication. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [Announce] Libgcrypt 1.6.3 released (with SCA fix) |
MISC |
lists.gnupg.org |
Patch, Vendor Advisory |
| Stealing Keys from PCs by Radio: Cheap Electromagnetic Attacks on Windowed Exponentiation |
MISC |
www.cs.tau.ac.il |
Third Party Advisory |
| Debian -- Security Information -- DSA-3185-1 libgcrypt11 |
MISC |
www.debian.org |
Third Party Advisory |
| [Announce] GnuPG 1.4.19 released (with SCA fix) |
MISC |
lists.gnupg.org |
Patch, Release Notes, Vendor Advisory |
| Debian -- Security Information -- DSA-3184-1 gnupg |
MISC |
www.debian.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296059 Oracle Solaris 11.4 Support Repository Update (SRU) 36.0.1.101.2 Missing (CPUJUL2021)