CVE-2014-3591
published 2019-11-29CVE-2014-3591: Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to…
PriorityP418medium4.2CVSS 3.1
AVPACHPRNUINSUCHINAN
EPSS
0.58%
43.7th percentile
Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using crafted ciphertext and the fluctuations in the electromagnetic field during multiplication.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libgcrypt20 | < libgcrypt20 1.6.3-2 (bookworm) | libgcrypt20 1.6.3-2 (bookworm) |
| gnu | gnupg | — | — |
| gnu | libgcrypt | — | — |
| gnupg | gnupg | < 1.4.19 | 1.4.19 |
| gnupg | gnupg | >= 0 < 1.4.16-1ubuntu2.3 | 1.4.16-1ubuntu2.3 |
| gnupg | libgcrypt | < 1.6.3 | 1.6.3 |
CVSS provenance
nvdv3.14.2MEDIUMCVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv4.2MEDIUM
vendor_debian4.2MEDIUM
vendor_redhat4.2MEDIUM
vendor_ubuntu4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Libgcrypt vulnerabilities
vendor_ubuntu·2015-04-01·CVSS 4.2
CVE-2014-3591 [MEDIUM] Libgcrypt vulnerabilities
Title: Libgcrypt vulnerabilities
Summary: Several security issues were fixed in Libgcrypt.
Daniel Genkin, Lev Pachmanov, Itamar Pipman, and Eran Tromer discovered
that Libgcrypt was susceptible to an attack via physical side channels. A
local attacker could use this attack to possibly recover private keys.
(CVE-2014-3591)
Daniel Genkin, Adi Shamir, and Eran Tromer discovered that Libgcrypt was
susceptible to an attack via physical side channels. A local attacker could
use this attack to possibly recover private keys. (CVE-2015-0837)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
GnuPG vulnerabilities
vendor_ubuntu·2015-04-01·CVSS 4.2
CVE-2014-3591 [MEDIUM] GnuPG vulnerabilities
Title: GnuPG vulnerabilities
Summary: Several security issues were fixed in GnuPG.
Daniel Genkin, Lev Pachmanov, Itamar Pipman, and Eran Tromer discovered
that GnuPG was susceptible to an attack via physical side channels. A local
attacker could use this attack to possibly recover private keys.
(CVE-2014-3591)
Daniel Genkin, Adi Shamir, and Eran Tromer discovered that GnuPG was
susceptible to an attack via physical side channels. A local attacker could
use this attack to possibly recover private keys. (CVE-2015-0837)
Hanno Böck discovered that GnuPG incorrectly handled certain malformed
keyrings. If a user or automated system were tricked into opening a
malformed keyring, a remote attacker could use this issue to cause GnuPG to
crash, resulting in a denial of service, or possibly execu
Red Hat
libgcrypt: use ciphertext blinding for Elgamal decryption (new side-channel attack)
vendor_redhat·2015-02-27·CVSS 4.2
CVE-2014-3591 [MEDIUM] libgcrypt: use ciphertext blinding for Elgamal decryption (new side-channel attack)
libgcrypt: use ciphertext blinding for Elgamal decryption (new side-channel attack)
Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using crafted ciphertext and the fluctuations in the electromagnetic field during multiplication.
Mitigation: In order to successfully exploit this flaw the attacker needs to following conditions:
1. They need to be very close to the system, in order to record the fluctuations in the electromagnetic waves being emitted by the system.
2. The attacker needs to send specially-crafted cipher text to the system for decryption.
3. The attacker needs to record the electromagnetic fluctuations when these
Debian
CVE-2014-3591: libgcrypt20 - Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext bli...
vendor_debian·2014·CVSS 4.2
CVE-2014-3591 [MEDIUM] CVE-2014-3591: libgcrypt20 - Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext bli...
Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using crafted ciphertext and the fluctuations in the electromagnetic field during multiplication.
Scope: local
bookworm: resolved (fixed in 1.6.3-2)
bullseye: resolved (fixed in 1.6.3-2)
forky: resolved (fixed in 1.6.3-2)
sid: resolved (fixed in 1.6.3-2)
trixie: resolved (fixed in 1.6.3-2)
GHSA
GHSA-5p8v-2xvp-pwmc: Libgcrypt before 1
ghsa_unreviewed·2022-05-17
CVE-2014-3591 [LOW] GHSA-5p8v-2xvp-pwmc: Libgcrypt before 1
Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using crafted ciphertext and the fluctuations in the electromagnetic field during multiplication.
OSV
CVE-2014-3591: Libgcrypt before 1
osv·2019-11-29·CVSS 4.2
CVE-2014-3591 [MEDIUM] CVE-2014-3591: Libgcrypt before 1
Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using crafted ciphertext and the fluctuations in the electromagnetic field during multiplication.
OSV
libgcrypt11, libgcrypt20 vulnerabilities
osv·2015-04-01·CVSS 4.2
CVE-2014-3591 [MEDIUM] libgcrypt11, libgcrypt20 vulnerabilities
libgcrypt11, libgcrypt20 vulnerabilities
Daniel Genkin, Lev Pachmanov, Itamar Pipman, and Eran Tromer discovered
that Libgcrypt was susceptible to an attack via physical side channels. A
local attacker could use this attack to possibly recover private keys.
(CVE-2014-3591)
Daniel Genkin, Adi Shamir, and Eran Tromer discovered that Libgcrypt was
susceptible to an attack via physical side channels. A local attacker could
use this attack to possibly recover private keys. (CVE-2015-0837)
OSV
gnupg, gnupg2 vulnerabilities
osv·2015-04-01·CVSS 4.2
CVE-2014-3591 [MEDIUM] gnupg, gnupg2 vulnerabilities
gnupg, gnupg2 vulnerabilities
Daniel Genkin, Lev Pachmanov, Itamar Pipman, and Eran Tromer discovered
that GnuPG was susceptible to an attack via physical side channels. A local
attacker could use this attack to possibly recover private keys.
(CVE-2014-3591)
Daniel Genkin, Adi Shamir, and Eran Tromer discovered that GnuPG was
susceptible to an attack via physical side channels. A local attacker could
use this attack to possibly recover private keys. (CVE-2015-0837)
Hanno Böck discovered that GnuPG incorrectly handled certain malformed
keyrings. If a user or automated system were tricked into opening a
malformed keyring, a remote attacker could use this issue to cause GnuPG to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2015-1606, CVE-2015-1607)
In
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-0837 CVE-2014-3591 gnupg: various flaws [fedora-all]
bugzilla·2015-03-03·CVSS 4.2
CVE-2015-0837 [MEDIUM] CVE-2015-0837 CVE-2014-3591 gnupg: various flaws [fedora-all]
CVE-2015-0837 CVE-2014-3591 gnupg: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While on
Bugzilla
CVE-2015-0837 CVE-2014-3591 mingw-libgcrypt: various flaws [epel-all]
bugzilla·2015-03-03·CVSS 4.2
CVE-2015-0837 [MEDIUM] CVE-2015-0837 CVE-2014-3591 mingw-libgcrypt: various flaws [epel-all]
CVE-2015-0837 CVE-2014-3591 mingw-libgcrypt: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
Bugzilla
CVE-2015-0837 CVE-2014-3591 libgcrypt: various flaws [fedora-all]
bugzilla·2015-03-03·CVSS 4.2
CVE-2015-0837 [MEDIUM] CVE-2015-0837 CVE-2014-3591 libgcrypt: various flaws [fedora-all]
CVE-2015-0837 CVE-2014-3591 libgcrypt: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whil
Bugzilla
CVE-2015-0837 CVE-2014-3591 mingw-libgcrypt: various flaws [fedora-all]
bugzilla·2015-03-03·CVSS 4.2
CVE-2015-0837 [MEDIUM] CVE-2015-0837 CVE-2014-3591 mingw-libgcrypt: various flaws [fedora-all]
CVE-2015-0837 CVE-2014-3591 mingw-libgcrypt: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora
Bugzilla
CVE-2014-3591 libgcrypt: use ciphertext blinding for Elgamal decryption (new side-channel attack)
bugzilla·2015-03-03·CVSS 4.2
CVE-2014-3591 [MEDIUM] CVE-2014-3591 libgcrypt: use ciphertext blinding for Elgamal decryption (new side-channel attack)
CVE-2014-3591 libgcrypt: use ciphertext blinding for Elgamal decryption (new side-channel attack)
Libgcrypt version 1.6.3 [1] and GnuPG version 1.4.19 [2] fix a side-channel attack which can potentially lead to an information leak.
This issue is different from CVE-2014-5270.
Relevant upstream commits:
- libgcrypt master
http://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=410d70bad9a650e3837055e36f157894ae49a57d
- libgcrypt 1.6.x CVE-2014-3591
http://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=d482948ac41768c36c5352a513fca8c50d2da4db
- libgcrypt 1.5.x CVE-2014-3591
http://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=35cd81f134c0da4e7e6fcfe40d270ee1251f52c2
- GnuPG 1.4.x CVE-2014-3591
http://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=com
http://www.cs.tau.ac.il/~tromer/radioexp/http://www.debian.org/security/2015/dsa-3184http://www.debian.org/security/2015/dsa-3185https://lists.gnupg.org/pipermail/gnupg-announce/2015q1/000363.htmlhttps://lists.gnupg.org/pipermail/gnupg-announce/2015q1/000364.htmlhttp://www.cs.tau.ac.il/~tromer/radioexp/http://www.debian.org/security/2015/dsa-3184http://www.debian.org/security/2015/dsa-3185https://lists.gnupg.org/pipermail/gnupg-announce/2015q1/000363.htmlhttps://lists.gnupg.org/pipermail/gnupg-announce/2015q1/000364.html
2019-11-29
Published