Libgcrypt CVE-2018-0495 Local Information Disclosure Vulnerability
BID:107967
Info
Libgcrypt CVE-2018-0495 Local Information Disclosure Vulnerability
| Bugtraq ID: | 107967 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2018-0495 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 13 2018 12:00AM |
| Updated: | Jun 13 2018 12:00AM |
| Credit: | Keegan Ryan of NCC Group |
| Vulnerable: |
Ubuntu Ubuntu Linux 18.10 Ubuntu Ubuntu Linux 18.04 LTS Ubuntu Ubuntu Linux 17.10 Ubuntu Ubuntu Linux 16.04 LTS Ubuntu Ubuntu Linux 14.04 LTS Ubuntu Ubuntu Linux 12.04 ESM Redhat JBoss Web Server (JWS) 3.0 Redhat JBoss EWS 2 Redhat Jboss EAP 6 Redhat JBoss Core Services 1 Redhat Enterprise Linux Workstation 7 Redhat Enterprise Linux Server 7 Redhat Enterprise Linux for Scientific Computing 7 Redhat Enterprise Linux for Power, little endian 7 Redhat Enterprise Linux for Power, big endian 7 Redhat Enterprise Linux for Power 9 7 Redhat Enterprise Linux for IBM z Systems 7 Redhat Enterprise Linux for IBM System z (Structure A) 7 Redhat Enterprise Linux for ARM 64 7 Redhat Enterprise Linux Desktop 7 Redhat Enterprise Linux 7 Redhat Enterprise Linux 6 Redhat Enterprise Linux 5 Redhat Ansible Tower 3.3 Oracle Traffic Director 11.1.1.9.0 OpenSSL Project OpenSSL 1.0 OpenSSL Project OpenSSL 1.0.1 Mozilla Network Security Services (NSS) 3.37.1 Mozilla Network Security Services (NSS) 3.36.7 Mozilla Network Security Services (NSS) 3.36.6 Mozilla Network Security Services (NSS) 3.36.5 Mozilla Network Security Services (NSS) 3.36.4 Mozilla Network Security Services (NSS) 3.36.3 Mozilla Network Security Services (NSS) 3.36.2 Mozilla Network Security Services (NSS) 3.36.1 Mozilla Network Security Services (NSS) 3.34.1 Mozilla Network Security Services (NSS) 3.31.1 Mozilla Network Security Services (NSS) 3.30.2 Mozilla Network Security Services (NSS) 3.30.1 Mozilla Network Security Services (NSS) 3.29.5 Mozilla Network Security Services (NSS) 3.29.4 Mozilla Network Security Services (NSS) 3.29.3 Mozilla Network Security Services (NSS) 3.29.2 Mozilla Network Security Services (NSS) 3.29.1 Mozilla Network Security Services (NSS) 3.28.4 Mozilla Network Security Services (NSS) 3.28 Mozilla Network Security Services (NSS) 3.21.4 Mozilla Network Security Services (NSS) 3.21.1 Mozilla Network Security Services (NSS) 3.20.2 Mozilla Network Security Services (NSS) 3.20.1 Mozilla Network Security Services (NSS) 3.19.1 Mozilla Network Security Services (NSS) 3.17.3 Mozilla Network Security Services (NSS) 3.17.1 Mozilla Network Security Services (NSS) 3.15.4 Mozilla Network Security Services (NSS) 3.15.3 Mozilla Network Security Services (NSS) 3.15.2 Mozilla Network Security Services (NSS) 3.15.1 Mozilla Network Security Services (NSS) 3.14.5 Mozilla Network Security Services (NSS) 3.14.4 Mozilla Network Security Services (NSS) 3.12.10 Mozilla Network Security Services (NSS) 3.12.8 Mozilla Network Security Services (NSS) 3.12.5 Mozilla Network Security Services (NSS) 3.12.4 Mozilla Network Security Services (NSS) 3.12.3 Mozilla Network Security Services (NSS) 3.12.2 Mozilla Network Security Services (NSS) 3.12.1 Mozilla Network Security Services (NSS) 3.11.3 Mozilla Network Security Services (NSS) 3.3.2 Mozilla Network Security Services (NSS) 3.3.1 Mozilla Network Security Services (NSS) 3.3 Mozilla Network Security Services (NSS) 3.2.1 Mozilla Network Security Services (NSS) 3.2 Mozilla Network Security Services (NSS) 3.37 Mozilla Network Security Services (NSS) 3.36 Mozilla Network Security Services (NSS) 3.35 Mozilla Network Security Services (NSS) 3.34 Mozilla Network Security Services (NSS) 3.33 Mozilla Network Security Services (NSS) 3.32 Mozilla Network Security Services (NSS) 3.31 Mozilla Network Security Services (NSS) 3.30 Mozilla Network Security Services (NSS) 3.29 Mozilla Network Security Services (NSS) 3.24.0 Mozilla Network Security Services (NSS) 3.23 Mozilla Network Security Services (NSS) 3.21 Mozilla Network Security Services (NSS) 3.20 Mozilla Network Security Services (NSS) 3.19.2.3 Mozilla Network Security Services (NSS) 3.17 Mozilla Network Security Services (NSS) 3.16.5 Mozilla Network Security Services (NSS) 3.16.2.1 Mozilla Network Security Services (NSS) 3.16 Mozilla Network Security Services (NSS) 3.15.5 Mozilla Network Security Services (NSS) 3.15.3.1 Mozilla Network Security Services (NSS) 3.15 Mozilla Network Security Services (NSS) 3.14.3 Mozilla Network Security Services (NSS) 3.14.2 Mozilla Network Security Services (NSS) 3.14.1 Mozilla Network Security Services (NSS) 3.14 Mozilla Network Security Services (NSS) 3.13.4 Mozilla Network Security Services (NSS) 3.13.3 Mozilla Network Security Services (NSS) 3.12.9 Mozilla Network Security Services (NSS) 3.12.7 Mozilla Network Security Services (NSS) 3.12.6 Mozilla Network Security Services (NSS) 3.12.3.2 Mozilla Network Security Services (NSS) 3.12.3.1 Mozilla Network Security Services (NSS) 3.12.11 Mozilla Network Security Services (NSS) 3.12 Mozilla Network Security Services (NSS) 3.11 Gnupg Libgcrypt 1.8.2 Gnupg Libgcrypt 1.8.1 Gnupg Libgcrypt 1.8 Gnupg Libgcrypt 1.7.8 Gnupg Libgcrypt 1.7.7 Gnupg Libgcrypt 1.7.3 Gnupg Libgcrypt 1.6.6 Gnupg Libgcrypt 1.6.1 Gnupg Libgcrypt 1.6 Gnupg Libgcrypt 1.5.6 Gnupg Libgcrypt 1.5.4 Gnupg Libgcrypt 1.6.3 Gnupg Libgcrypt 1.6.2 Gnupg Libgcrypt 1.5.3 Gnupg Libgcrypt 1.5.2 Gnupg Libgcrypt 1.5.1 Gnupg Libgcrypt 1.5.0 Gnupg Libgcrypt 1.4.6 Gnupg Libgcrypt 1.4.5 Gnupg Libgcrypt 1.4.4 Gnupg Libgcrypt 1.4.3 Gnupg Libgcrypt 1.4.0 |
| Not Vulnerable: |
OpenSSL Project OpenSSL 1.0.2 OpenSSL Project OpenSSL 1.1 Mozilla Network Security Services (NSS) 3.38 Gnupg Libgcrypt 1.8.3 Gnupg Libgcrypt 1.7.10 |
Exploit / POC
Libgcrypt CVE-2018-0495 Local Information Disclosure Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Libgcrypt CVE-2018-0495 Local Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Libgcrypt CVE-2018-0495 Local Information Disclosure Vulnerability
References:
References:
- Add blinding to an ECDSA signature (openssl)
- Add blinding to an ECDSA signature (openssl)
- Libgcrypt Homepage (gnu)
- Bug 1591163 (CVE-2018-0495) - CVE-2018-0495 openssl: ROHNP - Key Extraction Sid (Redhat)
- NSS 3.38 release notes (Mozilla)
- Side Channel Based (EC)DSA Key Extraction in Mozilla NSS (Mozilla)
- USN-3689-1: Libgcrypt vulnerability (Ubuntu)
- USN-3689-2: Libgcrypt vulnerability (Ubuntu)
- [Announce] Libgcrypt 1.8.3 and 1.7.10 to fix CVE-2018-0495 (gnupg.org)
- [SECURITY] [DLA 1405-1] libgcrypt20 security update (Debian)
- CVE-2018-0495 (gnupg.org)
- CVE-2018-0495 (Redhat)
- DSA-4231-1 libgcrypt20 -- security update (Debian)
- ecc: Add blinding for ECDSA. (gnupg.org)
- Oracle Critical Patch Update Advisory - April 2019 (Oracle)
- RHSA-2018:3221 - Security Advisory (Redhat)
- RHSA-2018:3505 - Security Advisory (Redhat)
- Technical Advisory: "ROHNP"- Key Extraction Side Channel in Multiple Crypto Libr (nccgroup.trust)
- USN-3850-1: NSS vulnerabilities (Ubuntu)
- USN-3850-2: NSS vulnerabilities (Ubuntu)