CVE-2019-13627
published 2019-09-25CVE-2019-13627: It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4…
PriorityP425medium6.3CVSS 3.1
AVLACHPRNUIRSUCHIHAN
EPSS
0.51%
40.1th percentile
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libgcrypt20 | < libgcrypt20 1.8.5-1 (bookworm) | libgcrypt20 1.8.5-1 (bookworm) |
| libgcrypt20_project | libgcrypt20 | — | — |
| libgcrypt20_project | libgcrypt20 | — | — |
| libgcrypt20_project | libgcrypt20 | — | — |
| libgcrypt20_project | libgcrypt20 | >= 0 < 1.8.5-1 | 1.8.5-1 |
| libgcrypt20_project | libgcrypt20 | >= 0 < 1.8.5-1 | 1.8.5-1 |
| libgcrypt20_project | libgcrypt20 | >= 0 < 1.8.5-1 | 1.8.5-1 |
| libgcrypt20_project | libgcrypt20 | >= 0 < 1.8.5-1 | 1.8.5-1 |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
nvdv2.02.6LOWAV:L/AC:H/Au:N/C:P/I:P/A:N
osv6.3MEDIUM
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Libgcrypt vulnerability
vendor_ubuntu·2020-01-28
CVE-2019-13627 Libgcrypt vulnerability
Title: Libgcrypt vulnerability
Summary: Libgcrypt could be made to expose sensitive information.
USN-4236-1 fixed a vulnerability in Libgcrypt. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that Libgcrypt was susceptible to a ECDSA timing attack.
An attacker could possibly use this attack to recover sensitive
information.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Libgcrypt vulnerability
vendor_ubuntu·2020-01-14
CVE-2019-13627 Libgcrypt vulnerability
Title: Libgcrypt vulnerability
Summary: Libgcrypt could be made to expose sensitive information.
USN-4236-1 fixed a vulnerability in Libgcrypt. This update provides the
corresponding fix for Ubuntu 16.04 LTS.
Original advisory details:
It was discovered that Libgcrypt was susceptible to a ECDSA timing attack.
An attacker could possibly use this attack to recover sensitive
information.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Libgcrypt vulnerability
vendor_ubuntu·2020-01-13
CVE-2019-13627 Libgcrypt vulnerability
Title: Libgcrypt vulnerability
Summary: Libgcrypt could be made to expose sensitive information.
It was discovered that Libgcrypt was susceptible to a ECDSA timing attack.
An attacker could possibly use this attack to recover sensitive
information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libgcrypt: ECDSA timing attack allowing private key leak
vendor_redhat·2019-10-02·CVSS 6.3
CVE-2019-13627 [MEDIUM] CWE-362 libgcrypt: ECDSA timing attack allowing private key leak
libgcrypt: ECDSA timing attack allowing private key leak
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.
A timing attack was found in the way ECCDSA was implemented in libgcrypt. A man-in-the-middle attacker could use this attack during signature generation to recover the private key. This attack is only feasible when the attacker is local to the machine where the signature is being generated. Attacks over the network or via the internet are not feasible.
Statement: The versions of libgcrypt shipped with Red Hat Enterprise Linux 5, 6 and 7 do not support ECC, therefore they are not affected by this flaw.
Package: libgcrypt (Red Hat
Debian
CVE-2019-13627: libgcrypt20 - It was discovered that there was a ECDSA timing attack in the libgcrypt20 crypto...
vendor_debian·2019·CVSS 6.3
CVE-2019-13627 [MEDIUM] CVE-2019-13627: libgcrypt20 - It was discovered that there was a ECDSA timing attack in the libgcrypt20 crypto...
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.
Scope: local
bookworm: resolved (fixed in 1.8.5-1)
bullseye: resolved (fixed in 1.8.5-1)
forky: resolved (fixed in 1.8.5-1)
sid: resolved (fixed in 1.8.5-1)
trixie: resolved (fixed in 1.8.5-1)
GHSA
GHSA-vwvj-6vw9-cw8w: It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library
ghsa_unreviewed·2022-05-24
CVE-2019-13627 [MEDIUM] CWE-203 GHSA-vwvj-6vw9-cw8w: It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.
OSV
CVE-2019-13627: It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library
osv·2019-09-25·CVSS 6.3
CVE-2019-13627 [MEDIUM] CVE-2019-13627: It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-13627 libgcrypt: ECDSA timing attack in the libgcrypt20 cryptographic library [fedora-all]
bugzilla·2019-10-22·CVSS 6.3
CVE-2019-13627 [MEDIUM] CVE-2019-13627 libgcrypt: ECDSA timing attack in the libgcrypt20 cryptographic library [fedora-all]
CVE-2019-13627 libgcrypt: ECDSA timing attack in the libgcrypt20 cryptographic library [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2019-13627 mingw-libgcrypt: libgcrypt: ECDSA timing attack in the libgcrypt20 cryptographic library [fedora-all]
bugzilla·2019-10-22·CVSS 6.3
CVE-2019-13627 [MEDIUM] CVE-2019-13627 mingw-libgcrypt: libgcrypt: ECDSA timing attack in the libgcrypt20 cryptographic library [fedora-all]
CVE-2019-13627 mingw-libgcrypt: libgcrypt: ECDSA timing attack in the libgcrypt20 cryptographic library [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this is
Bugzilla
CVE-2019-13627 libgcrypt: ECDSA timing attack allowing private key leak
bugzilla·2019-10-22·CVSS 6.3
CVE-2019-13627 [MEDIUM] CVE-2019-13627 libgcrypt: ECDSA timing attack allowing private key leak
CVE-2019-13627 libgcrypt: ECDSA timing attack allowing private key leak
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library
Fixed Release Info:
https://dev.gnupg.org/T4683
Upstream commits:
https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=b9577f7c89b4327edc09f2231bc8b31521102c79
https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=7c2943309d14407b51c8166c4dcecb56a3628567
https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=b9577f7c89b4327edc09f2231bc8b31521102c79 (master)
https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=7c2943309d14407b51c8166c4dcecb56a3628567 (master)
https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=d5407b78cca9f9d318a4f4d2f6ba2b8388584cd9
Bugzilla
CVE-2019-13627 mingw-libgcrypt: libgcrypt: ECDSA timing attack in the libgcrypt20 cryptographic library [epel-7]
bugzilla·2019-10-22·CVSS 6.3
CVE-2019-13627 [MEDIUM] CVE-2019-13627 mingw-libgcrypt: libgcrypt: ECDSA timing attack in the libgcrypt20 cryptographic library [epel-7]
CVE-2019-13627 mingw-libgcrypt: libgcrypt: ECDSA timing attack in the libgcrypt20 cryptographic library [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00060.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00018.htmlhttp://www.openwall.com/lists/oss-security/2019/10/02/2https://github.com/gpg/libgcrypt/releases/tag/libgcrypt-1.8.5https://lists.debian.org/debian-lts-announce/2019/09/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2020/01/msg00001.htmlhttps://minerva.crocs.fi.muni.cz/https://security-tracker.debian.org/tracker/CVE-2019-13627https://security.gentoo.org/glsa/202003-32https://usn.ubuntu.com/4236-1/https://usn.ubuntu.com/4236-2/https://usn.ubuntu.com/4236-3/http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00060.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00018.htmlhttp://www.openwall.com/lists/oss-security/2019/10/02/2https://github.com/gpg/libgcrypt/releases/tag/libgcrypt-1.8.5https://lists.debian.org/debian-lts-announce/2019/09/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2020/01/msg00001.htmlhttps://minerva.crocs.fi.muni.cz/https://security-tracker.debian.org/tracker/CVE-2019-13627https://security.gentoo.org/glsa/202003-32https://usn.ubuntu.com/4236-1/https://usn.ubuntu.com/4236-2/https://usn.ubuntu.com/4236-3/
2019-09-25
Published