CVE-2019-13627
Summary
| CVE | CVE-2019-13627 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-25 15:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| USN-4236-2: Libgcrypt vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| USN-4236-1: Libgcrypt vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| [SECURITY] [DLA 1931-2] libgcrypt20 regression update |
MLIST |
lists.debian.org |
Third Party Advisory |
| Release libgcrypt-1.8.5 · gpg/libgcrypt · GitHub |
MISC |
github.com |
Third Party Advisory |
| [security-announce] openSUSE-SU-2019:2161-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
Third Party Advisory |
| [security-announce] openSUSE-SU-2020:0022-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
Third Party Advisory |
| minerva.crocs.fi.muni.cz |
MISC |
minerva.crocs.fi.muni.cz |
Third Party Advisory |
| CVE-2019-13627 |
MISC |
security-tracker.debian.org |
Third Party Advisory |
| Libgcrypt: Side-channel attack (GLSA 202003-32) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| [SECURITY] [DLA 1931-1] libgcrypt20 security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| oss-security - Minerva: ECDSA key recovery from bit-length leakage |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| USN-4236-3: Libgcrypt vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296079 Oracle Solaris 11.4 Support Repository Update (SRU) 15.5.0 Missing (CPUOCT2019)
- 500294 Alpine Linux Security Update for libgcrypt
- 504060 Alpine Linux Security Update for libgcrypt
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 770068 Red Hat OpenShift Container Platform 4.6 Security Update (RHSA-2021:0436)
- 940271 AlmaLinux Security Update for libgcrypt (ALSA-2020:4482)
- 960748 Rocky Linux Security Update for libgcrypt (RLSA-2020:4482)