QID 354634
Date Published: 2023-01-02
QID 354634: Amazon Linux Security Advisory for libgcrypt : AL2012-2022-366
Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2021-33560:
1970096: CVE-2021-33560 libgcrypt: mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm
A side-channel attack flaw was found in the way libgcrypt implemented Elgamal encryption. This flaw allows an attacker to decrypt parts of ciphertext encrypted using Elgamal, for example, when using OpenPGP. The highest threat from this vulnerability is to confidentiality.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Administrators are advised to apply the appropriate software updates.
Vendor References
CVEs related to QID 354634
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| AL2012-2022-366 | Amazon Linux Bare Metal |
|