cbcvebase.
CVE-2019-13627
published 2019-09-25

CVE-2019-13627: It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4…

PriorityP425medium6.3CVSS 3.1
AVLACHPRNUIRSUCHIHAN
EPSS
0.51%
40.1th percentile
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.

Affected

16 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianlibgcrypt20< libgcrypt20 1.8.5-1 (bookworm)libgcrypt20 1.8.5-1 (bookworm)
libgcrypt20_projectlibgcrypt20
libgcrypt20_projectlibgcrypt20
libgcrypt20_projectlibgcrypt20
libgcrypt20_projectlibgcrypt20>= 0 < 1.8.5-11.8.5-1
libgcrypt20_projectlibgcrypt20>= 0 < 1.8.5-11.8.5-1
libgcrypt20_projectlibgcrypt20>= 0 < 1.8.5-11.8.5-1
libgcrypt20_projectlibgcrypt20>= 0 < 1.8.5-11.8.5-1
opensuseleap
opensuseleap

CVSS provenance

nvdv3.16.3MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
nvdv2.02.6LOWAV:L/AC:H/Au:N/C:P/I:P/A:N
osv6.3MEDIUM
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.