CVE-2015-0837
published 2019-11-29CVE-2015-0837: The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when…
PriorityP430medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.95%
78.0th percentile
The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libgcrypt20 | < libgcrypt20 1.6.3-2 (bookworm) | libgcrypt20 1.6.3-2 (bookworm) |
| gnu | gnupg | — | — |
| gnu | libgcrypt | — | — |
| gnupg | gnupg | < 1.4.19 | 1.4.19 |
| gnupg | gnupg | >= 0 < 1.4.16-1ubuntu2.3 | 1.4.16-1ubuntu2.3 |
| gnupg | libgcrypt | < 1.6.3 | 1.6.3 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Libgcrypt vulnerabilities
vendor_ubuntu·2015-04-01·CVSS 4.2
CVE-2014-3591 [MEDIUM] Libgcrypt vulnerabilities
Title: Libgcrypt vulnerabilities
Summary: Several security issues were fixed in Libgcrypt.
Daniel Genkin, Lev Pachmanov, Itamar Pipman, and Eran Tromer discovered
that Libgcrypt was susceptible to an attack via physical side channels. A
local attacker could use this attack to possibly recover private keys.
(CVE-2014-3591)
Daniel Genkin, Adi Shamir, and Eran Tromer discovered that Libgcrypt was
susceptible to an attack via physical side channels. A local attacker could
use this attack to possibly recover private keys. (CVE-2015-0837)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
GnuPG vulnerabilities
vendor_ubuntu·2015-04-01·CVSS 4.2
CVE-2014-3591 [MEDIUM] GnuPG vulnerabilities
Title: GnuPG vulnerabilities
Summary: Several security issues were fixed in GnuPG.
Daniel Genkin, Lev Pachmanov, Itamar Pipman, and Eran Tromer discovered
that GnuPG was susceptible to an attack via physical side channels. A local
attacker could use this attack to possibly recover private keys.
(CVE-2014-3591)
Daniel Genkin, Adi Shamir, and Eran Tromer discovered that GnuPG was
susceptible to an attack via physical side channels. A local attacker could
use this attack to possibly recover private keys. (CVE-2015-0837)
Hanno Böck discovered that GnuPG incorrectly handled certain malformed
keyrings. If a user or automated system were tricked into opening a
malformed keyring, a remote attacker could use this issue to cause GnuPG to
crash, resulting in a denial of service, or possibly execu
Red Hat
libgcrypt: last-level cache side-channel attack
vendor_redhat·2015-02-27·CVSS 5.9
CVE-2015-0837 [MEDIUM] libgcrypt: last-level cache side-channel attack
libgcrypt: last-level cache side-channel attack
The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."
Statement: Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw in the libgcrypt and gnupg2 packages.
The attack leading to this flaw, is difficult to conduct in practice especially for cross-vm environments, mainly because the attacker needs to run their timing attack script at the exact same time decryption runs on the victim machine. Also this is essentially a chosen ciphertext attack because the attacker pr
Debian
CVE-2015-0837: libgcrypt20 - The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows a...
vendor_debian·2015·CVSS 5.9
CVE-2015-0837 [MEDIUM] CVE-2015-0837: libgcrypt20 - The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows a...
The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."
Scope: local
bookworm: resolved (fixed in 1.6.3-2)
bullseye: resolved (fixed in 1.6.3-2)
forky: resolved (fixed in 1.6.3-2)
sid: resolved (fixed in 1.6.3-2)
trixie: resolved (fixed in 1.6.3-2)
GHSA
GHSA-3ccv-3j4f-926q: The mpi_powm function in Libgcrypt before 1
ghsa_unreviewed·2022-05-24
CVE-2015-0837 [MEDIUM] CWE-203 GHSA-3ccv-3j4f-926q: The mpi_powm function in Libgcrypt before 1
The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."
OSV
CVE-2015-0837: The mpi_powm function in Libgcrypt before 1
osv·2019-11-29·CVSS 5.9
CVE-2015-0837 [MEDIUM] CVE-2015-0837: The mpi_powm function in Libgcrypt before 1
The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."
OSV
libgcrypt11, libgcrypt20 vulnerabilities
osv·2015-04-01·CVSS 4.2
CVE-2014-3591 [MEDIUM] libgcrypt11, libgcrypt20 vulnerabilities
libgcrypt11, libgcrypt20 vulnerabilities
Daniel Genkin, Lev Pachmanov, Itamar Pipman, and Eran Tromer discovered
that Libgcrypt was susceptible to an attack via physical side channels. A
local attacker could use this attack to possibly recover private keys.
(CVE-2014-3591)
Daniel Genkin, Adi Shamir, and Eran Tromer discovered that Libgcrypt was
susceptible to an attack via physical side channels. A local attacker could
use this attack to possibly recover private keys. (CVE-2015-0837)
OSV
gnupg, gnupg2 vulnerabilities
osv·2015-04-01·CVSS 4.2
CVE-2014-3591 [MEDIUM] gnupg, gnupg2 vulnerabilities
gnupg, gnupg2 vulnerabilities
Daniel Genkin, Lev Pachmanov, Itamar Pipman, and Eran Tromer discovered
that GnuPG was susceptible to an attack via physical side channels. A local
attacker could use this attack to possibly recover private keys.
(CVE-2014-3591)
Daniel Genkin, Adi Shamir, and Eran Tromer discovered that GnuPG was
susceptible to an attack via physical side channels. A local attacker could
use this attack to possibly recover private keys. (CVE-2015-0837)
Hanno Böck discovered that GnuPG incorrectly handled certain malformed
keyrings. If a user or automated system were tricked into opening a
malformed keyring, a remote attacker could use this issue to cause GnuPG to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2015-1606, CVE-2015-1607)
In
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-0837 CVE-2014-3591 gnupg: various flaws [fedora-all]
bugzilla·2015-03-03·CVSS 4.2
CVE-2015-0837 [MEDIUM] CVE-2015-0837 CVE-2014-3591 gnupg: various flaws [fedora-all]
CVE-2015-0837 CVE-2014-3591 gnupg: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While on
Bugzilla
CVE-2015-0837 CVE-2014-3591 mingw-libgcrypt: various flaws [epel-all]
bugzilla·2015-03-03·CVSS 4.2
CVE-2015-0837 [MEDIUM] CVE-2015-0837 CVE-2014-3591 mingw-libgcrypt: various flaws [epel-all]
CVE-2015-0837 CVE-2014-3591 mingw-libgcrypt: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
Bugzilla
CVE-2015-0837 libgcrypt: last-level cache side-channel attack
bugzilla·2015-03-03·CVSS 5.9
CVE-2015-0837 [MEDIUM] CVE-2015-0837 libgcrypt: last-level cache side-channel attack
CVE-2015-0837 libgcrypt: last-level cache side-channel attack
Libgcrypt version 1.6.3 [1] and GnuPG version 1.4.19 [2] fix a side-channel attack on data-dependent timing variations in modular exponentiation, which can potentially lead to an information leak.
[1]: https://lists.gnupg.org/pipermail/gnupg-announce/2015q1/000364.html
[2]: https://lists.gnupg.org/pipermail/gnupg-announce/2015q1/000363.html
Discussion:
Created gnupg tracking bugs for this issue:
Affects: fedora-all [bug 1198154]
---
Created libgcrypt tracking bugs for this issue:
Affects: fedora-all [bug 1198152]
---
Created mingw-libgcrypt tracking bugs for this issue:
Affects: fedora-all [bug 1198153]
---
Created mingw-libgcrypt tracking bugs for this issue:
Affects: epel-all [bug 1198156]
---
gnupg-1.4.19-1.fc
Bugzilla
CVE-2015-0837 CVE-2014-3591 libgcrypt: various flaws [fedora-all]
bugzilla·2015-03-03·CVSS 4.2
CVE-2015-0837 [MEDIUM] CVE-2015-0837 CVE-2014-3591 libgcrypt: various flaws [fedora-all]
CVE-2015-0837 CVE-2014-3591 libgcrypt: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whil
Bugzilla
CVE-2015-0837 CVE-2014-3591 mingw-libgcrypt: various flaws [fedora-all]
bugzilla·2015-03-03·CVSS 4.2
CVE-2015-0837 [MEDIUM] CVE-2015-0837 CVE-2014-3591 mingw-libgcrypt: various flaws [fedora-all]
CVE-2015-0837 CVE-2014-3591 mingw-libgcrypt: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora
arXiv
Revisiting and Evaluating Software Side-channel Vulnerabilities and Countermeasures in Cryptographic Applications
arxiv_fulltext·2019-12-12
Revisiting and Evaluating Software Side-channel Vulnerabilities and Countermeasures in Cryptographic Applications
Revisiting and Evaluating Software Side-channel Vulnerabilities and Countermeasures in Cryptographic Applications
Tianwei Zhang
Nanyang Technological University
[email protected]
Jun Jiang
Two Sigma Investments, LP
[email protected]
Yinqian Zhang
The Ohio State University
[email protected]
dkgreenrgb0,0.6,0
grayrgb0.5,0.5,0.5
mauvergb0.58,0,0.82
frame=tb,
language=C,
aboveskip=3mm,
belowskip=3mm,
showstringspaces=false,
columns=flexible,
basicstyle= ,
numbers=left,
numbersep=-2pt,
numberstyle= ,
keywordstyle=blue,
commentstyle=dkgreen,
stringstyle=mauve,
breaklines=true,
breakatwhitespace=true,
tabsize=3
## Abstract
We systematize software side-channel attacks with a focus on vulnerabilities
and countermeasures in the cryptographic implementations. Particularly,
http://www.debian.org/security/2015/dsa-3184http://www.debian.org/security/2015/dsa-3185https://ieeexplore.ieee.org/document/7163050https://lists.gnupg.org/pipermail/gnupg-announce/2015q1/000363.htmlhttps://lists.gnupg.org/pipermail/gnupg-announce/2015q1/000364.htmlhttp://www.debian.org/security/2015/dsa-3184http://www.debian.org/security/2015/dsa-3185https://ieeexplore.ieee.org/document/7163050https://lists.gnupg.org/pipermail/gnupg-announce/2015q1/000363.htmlhttps://lists.gnupg.org/pipermail/gnupg-announce/2015q1/000364.html
2019-11-29
Published