Information disclosure in GnuPG - CVE-2014-3591
Published: November 29, 2019 / Updated: July 17, 2020
Vulnerability details
The vulnerability allows a local non-authenticated attacker to gain access to sensitive information.
Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using crafted ciphertext and the fluctuations in the electromagnetic field during multiplication.
Affected software
Amazon Linux AMI
Gentoo Linux
Fedora
Slackware Linux
gnupg1 (Alpine package)
gnupg
mingw-libgcrypt
libgcrypt
How to mitigate CVE-2014-3591
gnupg1 (Alpine package) - update to 1.4.19-r0
gnupg - addressed in versions 1.4.19-1.fc21, 1.4.19-1.fc22
mingw-libgcrypt - addressed in versions 1.6.3-1.el7, 1.6.3-1.fc21, 1.6.3-1.fc22
libgcrypt - addressed in versions 1.6.3-1.fc21, 1.6.3-1.fc22
External References
Related Security Bulletins
- Information disclosure in GNU GnuPG
- Information disclosure in gnupg1 (Alpine package)
- Amazon Linux AMI update for libgcrypt
- Gentoo update for GnuPG
- Slackware Linux update for gnupg
- Fedora 22 update for gnupg
- Fedora 21 update for gnupg
- Fedora 22 update for libgcrypt
- Fedora 21 update for libgcrypt
- Fedora 21 update for mingw-libgcrypt
- Fedora 22 update for mingw-libgcrypt
- Fedora EPEL 7 update for mingw-libgcrypt