CVE-2021-40528
published 2021-09-06CVE-2021-40528: The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain…
PriorityP430medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.42%
69.9th percentile
The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libgcrypt20 | < libgcrypt20 1.8.7-6 (bookworm) | libgcrypt20 1.8.7-6 (bookworm) |
| gnupg | libgcrypt | < 1.9.4 | 1.9.4 |
| msrc | cm1_libgcrypt_1.8.7-3_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_redhat7.5HIGH
vendor_debian5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_oracle5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Signaling (libgcrypt) — CVE-2021-40528
vendor_oracle·2023-07-15·CVSS 5.9
CVE-2021-40528 [MEDIUM] Oracle Oracle Communications Risk Matrix: Signaling (libgcrypt) — CVE-2021-40528
Oracle Oracle Communications Risk Matrix: Signaling (libgcrypt) vulnerability
CVE: CVE-2021-40528
CVSS: 5.9
Protocol: TCP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Install/Upgrade (Libgcrypt) — CVE-2021-40528
vendor_oracle·2023-01-15·CVSS 5.9
CVE-2021-40528 [MEDIUM] Oracle Oracle Communications Risk Matrix: Install/Upgrade (Libgcrypt) — CVE-2021-40528
Oracle Oracle Communications Risk Matrix: Install/Upgrade (Libgcrypt) vulnerability
CVE: CVE-2021-40528
CVSS: 5.9
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (GnuPG Libgcrypt) — CVE-2021-40528
vendor_oracle·2022-10-15·CVSS 5.9
CVE-2021-40528 [MEDIUM] Oracle Oracle Communications Risk Matrix: Configuration (GnuPG Libgcrypt) — CVE-2021-40528
Oracle Oracle Communications Risk Matrix: Configuration (GnuPG Libgcrypt) vulnerability
CVE: CVE-2021-40528
CVSS: 5.9
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Ubuntu
Libgcrypt vulnerabilities
vendor_ubuntu·2021-09-16
CVE-2021-33560 Libgcrypt vulnerabilities
Title: Libgcrypt vulnerabilities
Summary: Libgcrypt could be made to expose sensitive information.
USN-5080-1 fixed several vulnerabilities in Libgcrypt. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that Libgcrypt incorrectly handled ElGamal encryption. An
attacker could possibly use this issue to recover sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Libgcrypt vulnerabilities
vendor_ubuntu·2021-09-16
CVE-2021-33560 Libgcrypt vulnerabilities
Title: Libgcrypt vulnerabilities
Summary: Libgcrypt could be made to expose sensitive information.
It was discovered that Libgcrypt incorrectly handled ElGamal encryption. An
attacker could possibly use this issue to recover sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because during interaction between two cryptographic libraries a certain dangerous combination of the prime defined by th
vendor_msrc·2021-09-14·CVSS 5.9
CVE-2021-40528 [MEDIUM] CWE-327 The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because during interaction between two cryptographic libraries a certain dangerous combination of the prime defined by th
The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because during interaction between two cryptographic libraries a certain dangerous combination of the prime defined by the receiver's public key the generator defined by the receiver's public key and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this wo
Red Hat
libgcrypt: ElGamal implementation allows plaintext recovery
vendor_redhat·2021-07-20·CVSS 7.5
CVE-2021-40528 [HIGH] libgcrypt: ElGamal implementation allows plaintext recovery
libgcrypt: ElGamal implementation allows plaintext recovery
The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.
A flaw was found in libgcrypt's ElGamal implementation, where it allows plain text recovery. During the interaction between two cryptographic libraries, a certain combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against
Debian
CVE-2021-40528: libgcrypt20 - The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery b...
vendor_debian·2021·CVSS 5.9
CVE-2021-40528 [MEDIUM] CVE-2021-40528: libgcrypt20 - The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery b...
The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.
Scope: local
bookworm: resolved (fixed in 1.8.7-6)
bullseye: resolved (fixed in 1.8.7-6)
forky: resolved (fixed in 1.8.7-6)
sid: resolved (fixed in 1.8.7-6)
trixie: resolved (fixed in 1.8.7-6)
GHSA
GHSA-8m2v-68m9-q2c7: The ElGamal implementation in Libgcrypt before 1
ghsa_unreviewed·2022-05-24
CVE-2021-40528 [MEDIUM] CWE-327 GHSA-8m2v-68m9-q2c7: The ElGamal implementation in Libgcrypt before 1
The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.
OSV
CVE-2021-40528: The ElGamal implementation in Libgcrypt before 1
osv·2021-09-06·CVSS 5.9
CVE-2021-40528 [MEDIUM] CVE-2021-40528: The ElGamal implementation in Libgcrypt before 1
The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://eprint.iacr.org/2021/923https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=3462280f2e23e16adf3ed5176e0f2413d8861320https://ibm.github.io/system-security-research-updates/2021/07/20/insecurity-elgamal-pt1https://ibm.github.io/system-security-research-updates/2021/09/06/insecurity-elgamal-pt2https://security.gentoo.org/glsa/202210-13https://eprint.iacr.org/2021/923https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=3462280f2e23e16adf3ed5176e0f2413d8861320https://ibm.github.io/system-security-research-updates/2021/07/20/insecurity-elgamal-pt1https://ibm.github.io/system-security-research-updates/2021/09/06/insecurity-elgamal-pt2https://security.gentoo.org/glsa/202210-13
2021-09-06
Published