CVE-2017-7526
published 2018-07-26CVE-2017-7526: libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method…
PriorityP339medium6.8CVSS 3.0
AVNACHPRNUINSCCHINAN
EPSS
3.89%
89.1th percentile
libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method for computing the sliding-window expansion. The same attack is believed to work on RSA-2048 with moderately more computation. This side-channel requires that attacker can run arbitrary software on the hardware where the private RSA key is used.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | gnupg1 | < gnupg1 1.4.22-1 (bookworm) | gnupg1 1.4.22-1 (bookworm) |
| debian | gnupg2 | < gnupg1 1.4.22-1 (bookworm) | gnupg1 1.4.22-1 (bookworm) |
| debian | libgcrypt20 | < gnupg1 1.4.22-1 (bookworm) | gnupg1 1.4.22-1 (bookworm) |
| gnupg | libgcrypt | < 1.7.8 | 1.7.8 |
| gnupg | libgcrypt | — | — |
CVSS provenance
nvdv3.06.8MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.8MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GnuPG vulnerability
vendor_ubuntu·2018-08-15
CVE-2017-7526 GnuPG vulnerability
Title: GnuPG vulnerability
Summary: GnuPG could be made to expose sensitive information.
USN-3733-1 fixed a vulnerability in GnuPG. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Daniel J. Bernstein, Joachim Breitner, Daniel Genkin, Leon Groot Bruinderink,
Nadia Heninger, Tanja Lange, Christine van Vredendaal, and Yuval Yarom
discovered that GnuPG is vulnerable to a cache side-channel attack. A local
attacker could use this attack to recover RSA private keys.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
GnuPG vulnerability
vendor_ubuntu·2018-08-07
CVE-2017-7526 GnuPG vulnerability
Title: GnuPG vulnerability
Summary: GnuPG could be made to expose sensitive information.
Daniel J. Bernstein, Joachim Breitner, Daniel Genkin, Leon Groot Bruinderink,
Nadia Heninger, Tanja Lange, Christine van Vredendaal, and Yuval Yarom
discovered that GnuPG is vulnerable to a cache side-channel attack. A local
attacker could use this attack to recover RSA private keys.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Libgcrypt vulnerability
vendor_ubuntu·2017-07-17·CVSS 6.1
CVE-2017-7526 [MEDIUM] Libgcrypt vulnerability
Title: Libgcrypt vulnerability
Summary: Several security issues were fixed in Libgcrypt.
USN-3347-1 fixed a vulnerability in Libgcrypt. This update provides the
corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Daniel J. Bernstein, Joachim Breitner, Daniel Genkin, Leon Groot
Bruinderink, Nadia Heninger, Tanja Lange, Christine van Vredendaal, and
Yuval Yarom discovered that Libgcrypt was susceptible to an attack via
side channels. A local attacker could use this attack to recover RSA
private keys. (CVE-2017-7526)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Libgcrypt vulnerabilities
vendor_ubuntu·2017-07-03·CVSS 6.1
CVE-2017-7526 [MEDIUM] Libgcrypt vulnerabilities
Title: Libgcrypt vulnerabilities
Summary: Several security issues were fixed in Libgcrypt.
Daniel J. Bernstein, Joachim Breitner, Daniel Genkin, Leon Groot
Bruinderink, Nadia Heninger, Tanja Lange, Christine van Vredendaal, and
Yuval Yarom discovered that Libgcrypt was susceptible to an attack via
side channels. A local attacker could use this attack to recover RSA
private keys. (CVE-2017-7526)
It was discovered that Libgcrypt was susceptible to an attack via
side channels. A local attacker could use this attack to possibly recover
EdDSA private keys. This issue only applied to Ubuntu 16.04 LTS, Ubuntu
16.10 and Ubuntu 17.04. (CVE-2017-9526)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libgcrypt: Use of left-to-right sliding window method allows full RSA key recovery
vendor_redhat·2017-06-29·CVSS 6.1
CVE-2017-7526 [MEDIUM] CWE-200 libgcrypt: Use of left-to-right sliding window method allows full RSA key recovery
libgcrypt: Use of left-to-right sliding window method allows full RSA key recovery
libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method for computing the sliding-window expansion. The same attack is believed to work on RSA-2048 with moderately more computation. This side-channel requires that attacker can run arbitrary software on the hardware where the private RSA key is used.
Statement: This side-channel attack requires that the attacker can run arbitrary software on the hardware where the private RSA key is used. Allowing execute access to a box with private keys should be considered as an unsafe security practice, anyway. Thus in practice there are easier ways to access the private
Debian
CVE-2017-7526: gnupg1 - libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resu...
vendor_debian·2017·CVSS 6.1
CVE-2017-7526 [MEDIUM] CVE-2017-7526: gnupg1 - libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resu...
libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method for computing the sliding-window expansion. The same attack is believed to work on RSA-2048 with moderately more computation. This side-channel requires that attacker can run arbitrary software on the hardware where the private RSA key is used.
Scope: local
bookworm: resolved (fixed in 1.4.22-1)
bullseye: resolved (fixed in 1.4.22-1)
forky: resolved (fixed in 1.4.22-1)
sid: resolved (fixed in 1.4.22-1)
trixie: resolved (fixed in 1.4.22-1)
GHSA
GHSA-f2v5-c455-qhg2: libgcrypt before version 1
ghsa_unreviewed·2022-05-13
CVE-2017-7526 [MEDIUM] GHSA-f2v5-c455-qhg2: libgcrypt before version 1
libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method for computing the sliding-window expansion. The same attack is believed to work on RSA-2048 with moderately more computation. This side-channel requires that attacker can run arbitrary software on the hardware where the private RSA key is used.
OSV
CVE-2017-7526: libgcrypt before version 1
osv·2018-07-26·CVSS 6.8
CVE-2017-7526 [MEDIUM] CVE-2017-7526: libgcrypt before version 1
libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method for computing the sliding-window expansion. The same attack is believed to work on RSA-2048 with moderately more computation. This side-channel requires that attacker can run arbitrary software on the hardware where the private RSA key is used.
OSV
libgcrypt11, libgcrypt20 vulnerabilities
osv·2017-07-03·CVSS 6.8
CVE-2017-7526 [MEDIUM] libgcrypt11, libgcrypt20 vulnerabilities
libgcrypt11, libgcrypt20 vulnerabilities
Daniel J. Bernstein, Joachim Breitner, Daniel Genkin, Leon Groot
Bruinderink, Nadia Heninger, Tanja Lange, Christine van Vredendaal, and
Yuval Yarom discovered that Libgcrypt was susceptible to an attack via
side channels. A local attacker could use this attack to recover RSA
private keys. (CVE-2017-7526)
It was discovered that Libgcrypt was susceptible to an attack via
side channels. A local attacker could use this attack to possibly recover
EdDSA private keys. This issue only applied to Ubuntu 16.04 LTS, Ubuntu
16.10 and Ubuntu 17.04. (CVE-2017-9526)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7526 libgcrypt: Use of left-to-right sliding window method allows full RSA key recovery [fedora-all]
bugzilla·2017-06-29·CVSS 6.1
CVE-2017-7526 [MEDIUM] CVE-2017-7526 libgcrypt: Use of left-to-right sliding window method allows full RSA key recovery [fedora-all]
CVE-2017-7526 libgcrypt: Use of left-to-right sliding window method allows full RSA key recovery [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2017-7526 mingw-libgcrypt: libgcrypt: Use of left-to-right sliding window method allows full RSA key recovery [epel-7]
bugzilla·2017-06-29·CVSS 6.1
CVE-2017-7526 [MEDIUM] CVE-2017-7526 mingw-libgcrypt: libgcrypt: Use of left-to-right sliding window method allows full RSA key recovery [epel-7]
CVE-2017-7526 mingw-libgcrypt: libgcrypt: Use of left-to-right sliding window method allows full RSA key recovery [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion
Bugzilla
CVE-2017-7526 mingw-libgcrypt: libgcrypt: Use of left-to-right sliding window method allows full RSA key recovery [fedora-all]
bugzilla·2017-06-29·CVSS 6.1
CVE-2017-7526 [MEDIUM] CVE-2017-7526 mingw-libgcrypt: libgcrypt: Use of left-to-right sliding window method allows full RSA key recovery [fedora-all]
CVE-2017-7526 mingw-libgcrypt: libgcrypt: Use of left-to-right sliding window method allows full RSA key recovery [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOT
Bugzilla
CVE-2017-7526 libgcrypt: Use of left-to-right sliding window method allows full RSA key recovery
bugzilla·2017-06-29·CVSS 6.1
CVE-2017-7526 [MEDIUM] CVE-2017-7526 libgcrypt: Use of left-to-right sliding window method allows full RSA key recovery
CVE-2017-7526 libgcrypt: Use of left-to-right sliding window method allows full RSA key recovery
Libgcrypt's RSA-1024 implementation using left-to-right method for computing the sliding-window expansion was found to be vulnerable to cache side-channel attack resulting into complete break of RSA-1024. The same attack is believed to work on RSA-2048 with moderately more computation. This side-channel requires that attacker can run arbitrary software on the hardware where the private RSA key is used.
Upstream patches:
https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=8725c99ffa41778f382ca97233183bcd687bb0ce
https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=78130828e9a140a9de4dafadbc844dbb64cb709a
https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a
http://www.securityfocus.com/bid/99338http://www.securitytracker.com/id/1038915https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7526https://eprint.iacr.org/2017/627https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=78130828e9a140a9de4dafadbc844dbb64cb709ahttps://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=8725c99ffa41778f382ca97233183bcd687bb0cehttps://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=e6a3dc9900433bbc8ad362a595a3837318c28fa9https://lists.gnupg.org/pipermail/gnupg-announce/2017q2/000408.htmlhttps://usn.ubuntu.com/3733-1/https://usn.ubuntu.com/3733-2/https://www.debian.org/security/2017/dsa-3901https://www.debian.org/security/2017/dsa-3960http://www.securityfocus.com/bid/99338http://www.securitytracker.com/id/1038915https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7526https://eprint.iacr.org/2017/627https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=78130828e9a140a9de4dafadbc844dbb64cb709ahttps://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=8725c99ffa41778f382ca97233183bcd687bb0cehttps://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=e6a3dc9900433bbc8ad362a595a3837318c28fa9https://lists.gnupg.org/pipermail/gnupg-announce/2017q2/000408.htmlhttps://usn.ubuntu.com/3733-1/https://usn.ubuntu.com/3733-2/https://www.debian.org/security/2017/dsa-3901https://www.debian.org/security/2017/dsa-3960
2018-07-26
Published