QID 670963
Date Published: 2021-11-24
QID 670963: EulerOS Security Update for libgcrypt (EulerOS-SA-2021-2590)
Libgcrypt is a general purpose crypto library based on the code used in GNU Privacy Guard. This is a development version.
Security Fix(es):
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. (There is also an interoperability problem because the selection of the k integer value does not properly consider the differences between basic ElGamal encryption and generalized ElGamal encryption.) This, for example, affects use of ElGamal in OpenPGP.(CVE-2021-33560)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
An arbitrary attacker may exploit this vulnerability to compromise the system.
CVEs related to QID 670963
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| EulerOS-SA-2021-2590 | EulerOS V2.0SP3 |
|