Cryptographic issues in Libgcrypt - CVE-2019-13627

 

Cryptographic issues in Libgcrypt - CVE-2019-13627

Published: January 29, 2020


Vulnerability identifier: #VU24721
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13627
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform timing attack.

The vulnerability exists due to an error within the libgcrypt20 cryptographic library. A remote attacker can perform ECDSA timing attack.


Affected software

Libgcrypt
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Opensuse
Service Telemetry Framework
libgcrypt (Alpine package)
libgcrypt (Red Hat package)
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Tivoli Storage Manager
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)

How to mitigate CVE-2019-13627

Install updates from vendor's website.

Libgcrypt - update to 1.8.5
libgcrypt (Alpine package) - update to 1.8.3-r2
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.11.0, 1.12.0
Quay - update to 3.3.3
libgcrypt (Red Hat package) - update to 1.8.5-4.el8
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.2.0.5.009
Dell EMC Unity XT Operating Environment (OE) - update to 5.0.2.0.5.009
Dell EMC Unity Operating Environment (OE) - update to 5.0.2.0.5.009

External References

Related Security Bulletins