CVE-2013-4242
published 2013-08-19CVE-2013-4242: GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache…
PriorityP47low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.53%
41.4th percentile
GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.
Affected
93 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| gnupg | gnupg | <= 1.4.13 | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rpp2-q7rq-p78j: GnuPG before 1
ghsa_unreviewed·2022-05-14
CVE-2013-4242 [LOW] CWE-200 GHSA-rpp2-q7rq-p78j: GnuPG before 1
GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.
Ubuntu
GnuPG, Libgcrypt vulnerability
vendor_ubuntu·2013-08-01
CVE-2013-4242 GnuPG, Libgcrypt vulnerability
Title: GnuPG, Libgcrypt vulnerability
Summary: GnuPG and Libgcrypt could be made to expose sensitive information.
Yuval Yarom and Katrina Falkner discovered a timing-based information leak,
known as Flush+Reload, that could be used to trace execution in programs.
GnuPG and Libgcrypt followed different execution paths based on key-related
data, which could be used to expose the contents of private keys.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
GnuPG susceptible to Yarom/Falkner flush+reload cache side-channel attack
vendor_redhat·2013-07-22·CVSS 1.9
CVE-2013-4242 [LOW] GnuPG susceptible to Yarom/Falkner flush+reload cache side-channel attack
GnuPG susceptible to Yarom/Falkner flush+reload cache side-channel attack
GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.
Statement: This issue affects the version of gnupg as shipped with Red Hat Enterprise Linux 5. This issue affects the version of libgcrypt as shipped with Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this issue as having moderate security impact, a future update may address this flaw. More technical details on this flaw are available at https://bugzilla.redhat.com/show_bug.cgi?id=988589#c12
Package: libgcrypt (Red Hat Enterprise Linux 7) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-5270 libgcrypt: ELGAMAL side-channel attack
bugzilla·2014-08-11·CVSS 1.9
CVE-2014-5270 [LOW] CVE-2014-5270 libgcrypt: ELGAMAL side-channel attack
CVE-2014-5270 libgcrypt: ELGAMAL side-channel attack
It was reported that libgcrypt was vulnerable to an ELGAMAL side-channel attack:
https://lists.fedoraproject.org/pipermail/security-team/2014-August/000055.html
http://lists.gnupg.org/pipermail/gnupg-announce/2014q3/000352.html
In the above reports, this issue presented when using GnuPG with a version of libgcrypt older than 1.6.0 or older than 1.5.4.
Similar to CVE-2013-4242/bug 988589, this could possibly be used to obtain the majority of a private key from memory.
References:
http://www.cs.unc.edu/~reiter/papers/2012/CCS.pdf
Discussion:
Created mingw32-libgcrypt tracking bugs for this issue:
Affects: epel-5 [bug 1128532]
---
Created mingw-libgcrypt tracking bugs for this issue:
Affects: fedora-all [bug 1128533]
---
CVE r
Bugzilla
CVE-2013-4242 GnuPG susceptible to Yarom/Falkner flush+reload cache side-channel attack
bugzilla·2013-07-25·CVSS 1.9
CVE-2013-4242 [LOW] CVE-2013-4242 GnuPG susceptible to Yarom/Falkner flush+reload cache side-channel attack
CVE-2013-4242 GnuPG susceptible to Yarom/Falkner flush+reload cache side-channel attack
It was announced that GnuPG 1.x [1] and Libgcrypt [2] were susceptible to the Yarom/Falkner flush+reload cache side-channel attack on the RSA secret exponent, which can be used to obtain the majority of an RSA secret key from memory. An abstract of the paper is noted below:
Flush+Reload is a cache side-channel attack that monitors access to
data in shared pages. In this paper we demonstrate how to use the
attack to extract private encryption keys from GnuPG. The high
resolution and low noise of the Flush+Reload attack enables a spy
program to recover over 98% of the bits of the private key in a
single decryption or signing round. Unlike previous attacks, the
attack targets the last level L3 cache. Con
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=717880http://eprint.iacr.org/2013/448http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.gnupg.org/pipermail/gnupg-announce/2013q3/000330.htmlhttp://lists.opensuse.org/opensuse-updates/2013-08/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1457.htmlhttp://secunia.com/advisories/54318http://secunia.com/advisories/54321http://secunia.com/advisories/54332http://secunia.com/advisories/54375http://www.debian.org/security/2013/dsa-2730http://www.debian.org/security/2013/dsa-2731http://www.kb.cert.org/vuls/id/976534http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/61464http://www.ubuntu.com/usn/USN-1923-1http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=717880http://eprint.iacr.org/2013/448http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.gnupg.org/pipermail/gnupg-announce/2013q3/000330.htmlhttp://lists.opensuse.org/opensuse-updates/2013-08/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1457.htmlhttp://secunia.com/advisories/54318http://secunia.com/advisories/54321http://secunia.com/advisories/54332http://secunia.com/advisories/54375http://www.debian.org/security/2013/dsa-2730http://www.debian.org/security/2013/dsa-2731http://www.kb.cert.org/vuls/id/976534http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/61464http://www.ubuntu.com/usn/USN-1923-1
2013-08-19
Published