CVE-2014-5270
published 2014-10-10CVE-2014-5270: Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it…
PriorityP48low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.53%
41.2th percentile
Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libgcrypt20 | < libgcrypt20 1.6.0-2 (bookworm) | libgcrypt20 1.6.0-2 (bookworm) |
| gnupg | libgcrypt | <= 1.5.3 | — |
| gnupg | libgcrypt | — | — |
| gnupg | libgcrypt | — | — |
| gnupg | libgcrypt | — | — |
| gnupg | libgcrypt | — | — |
| gnupg | libgcrypt | — | — |
| gnupg | libgcrypt | — | — |
| gnupg | libgcrypt | — | — |
| gnupg | libgcrypt | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_ubuntu4.2MEDIUM
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-47gj-9v97-r4c7: Libgcrypt before 1
ghsa_unreviewed·2022-05-17·CVSS 2.1
CVE-2014-5270 [LOW] CWE-200 GHSA-47gj-9v97-r4c7: Libgcrypt before 1
Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576.
OSV
CVE-2014-5270: Libgcrypt before 1
osv·2014-10-10·CVSS 2.1
CVE-2014-5270 [LOW] CVE-2014-5270: Libgcrypt before 1
Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576.
Ubuntu
GnuPG vulnerabilities
vendor_ubuntu·2015-04-01·CVSS 4.2
CVE-2014-3591 [MEDIUM] GnuPG vulnerabilities
Title: GnuPG vulnerabilities
Summary: Several security issues were fixed in GnuPG.
Daniel Genkin, Lev Pachmanov, Itamar Pipman, and Eran Tromer discovered
that GnuPG was susceptible to an attack via physical side channels. A local
attacker could use this attack to possibly recover private keys.
(CVE-2014-3591)
Daniel Genkin, Adi Shamir, and Eran Tromer discovered that GnuPG was
susceptible to an attack via physical side channels. A local attacker could
use this attack to possibly recover private keys. (CVE-2015-0837)
Hanno Böck discovered that GnuPG incorrectly handled certain malformed
keyrings. If a user or automated system were tricked into opening a
malformed keyring, a remote attacker could use this issue to cause GnuPG to
crash, resulting in a denial of service, or possibly execu
Ubuntu
GnuPG vulnerability
vendor_ubuntu·2014-09-03
CVE-2014-5270 GnuPG vulnerability
Title: GnuPG vulnerability
Summary: GnuPG could expose sensitive information when performing decryption.
Daniel Genkin, Adi Shamir, and Eran Tromer discovered that GnuPG was
susceptible to an adaptive chosen ciphertext attack via physical side
channels. A local attacker could use this attack to possibly recover
private keys.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Libgcrypt vulnerability
vendor_ubuntu·2014-09-03
CVE-2014-5270 Libgcrypt vulnerability
Title: Libgcrypt vulnerability
Summary: Libgcrypt could expose sensitive information when performing decryption.
Daniel Genkin, Adi Shamir, and Eran Tromer discovered that Libgcrypt was
susceptible to an adaptive chosen ciphertext attack via physical side
channels. A local attacker could use this attack to possibly recover
private keys.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libgcrypt: ELGAMAL side-channel attack
vendor_redhat·2014-08-08·CVSS 2.1
CVE-2014-5270 [LOW] libgcrypt: ELGAMAL side-channel attack
libgcrypt: ELGAMAL side-channel attack
Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576.
Package: gnupg (Red Hat Enterprise Linux 5) - Will not fix
Package: libgcrypt (Red Hat Enterprise Linux 5) - Will not fix
Package: libgcrypt (Red Hat Enterprise Linux 6) - Will not fix
Package: libgcrypt (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2014-5270: libgcrypt20 - Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly p...
vendor_debian·2014·CVSS 2.1
CVE-2014-5270 [LOW] CVE-2014-5270: libgcrypt20 - Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly p...
Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576.
Scope: local
bookworm: resolved (fixed in 1.6.0-2)
bullseye: resolved (fixed in 1.6.0-2)
forky: resolved (fixed in 1.6.0-2)
sid: resolved (fixed in 1.6.0-2)
trixie: resolved (fixed in 1.6.0-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3591 libgcrypt: use ciphertext blinding for Elgamal decryption (new side-channel attack)
bugzilla·2015-03-03·CVSS 4.2
CVE-2014-3591 [MEDIUM] CVE-2014-3591 libgcrypt: use ciphertext blinding for Elgamal decryption (new side-channel attack)
CVE-2014-3591 libgcrypt: use ciphertext blinding for Elgamal decryption (new side-channel attack)
Libgcrypt version 1.6.3 [1] and GnuPG version 1.4.19 [2] fix a side-channel attack which can potentially lead to an information leak.
This issue is different from CVE-2014-5270.
Relevant upstream commits:
- libgcrypt master
http://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=410d70bad9a650e3837055e36f157894ae49a57d
- libgcrypt 1.6.x CVE-2014-3591
http://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=d482948ac41768c36c5352a513fca8c50d2da4db
- libgcrypt 1.5.x CVE-2014-3591
http://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=35cd81f134c0da4e7e6fcfe40d270ee1251f52c2
- GnuPG 1.4.x CVE-2014-3591
http://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=com
Bugzilla
CVE-2014-5270 libgcrypt: ELGAMAL side-channel attack
bugzilla·2014-08-11·CVSS 1.9
CVE-2014-5270 [LOW] CVE-2014-5270 libgcrypt: ELGAMAL side-channel attack
CVE-2014-5270 libgcrypt: ELGAMAL side-channel attack
It was reported that libgcrypt was vulnerable to an ELGAMAL side-channel attack:
https://lists.fedoraproject.org/pipermail/security-team/2014-August/000055.html
http://lists.gnupg.org/pipermail/gnupg-announce/2014q3/000352.html
In the above reports, this issue presented when using GnuPG with a version of libgcrypt older than 1.6.0 or older than 1.5.4.
Similar to CVE-2013-4242/bug 988589, this could possibly be used to obtain the majority of a private key from memory.
References:
http://www.cs.unc.edu/~reiter/papers/2012/CCS.pdf
Discussion:
Created mingw32-libgcrypt tracking bugs for this issue:
Affects: epel-5 [bug 1128532]
---
Created mingw-libgcrypt tracking bugs for this issue:
Affects: fedora-all [bug 1128533]
---
CVE r
http://lists.gnupg.org/pipermail/gnupg-announce/2014q3/000352.htmlhttp://openwall.com/lists/oss-security/2014/08/16/2http://www.cs.tau.ac.il/~tromer/handsoff/http://www.debian.org/security/2014/dsa-3024http://www.debian.org/security/2014/dsa-3073http://lists.gnupg.org/pipermail/gnupg-announce/2014q3/000352.htmlhttp://openwall.com/lists/oss-security/2014/08/16/2http://www.cs.tau.ac.il/~tromer/handsoff/http://www.debian.org/security/2014/dsa-3024http://www.debian.org/security/2014/dsa-3073
2014-10-10
Published