Information disclosure in Libgcrypt - CVE-2017-0379
Published: August 30, 2017 / Updated: July 28, 2020
Vulnerability identifier: #VU32070
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-0379
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.c.
Affected software
Libgcrypt
Arch Linux
Slackware Linux
Fedora
libgcrypt (Alpine package)
libgcrypt
Oracle Communications WebRTC Session Controller
Arch Linux
Slackware Linux
Fedora
libgcrypt (Alpine package)
libgcrypt
Oracle Communications WebRTC Session Controller
How to mitigate CVE-2017-0379
Install update from vendor's website.
Libgcrypt - update to 1.8.1
libgcrypt (Alpine package) - update to 1.7.9-r0
libgcrypt - addressed in versions 1.7.9-1.fc25, 1.7.9-1.fc26, 1.8.1-1.fc27
Oracle Communications WebRTC Session Controller - update to 7.2
libgcrypt (Alpine package) - update to 1.7.9-r0
libgcrypt - addressed in versions 1.7.9-1.fc25, 1.7.9-1.fc26, 1.8.1-1.fc27
Oracle Communications WebRTC Session Controller - update to 7.2
External References
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.securityfocus.com/bid/100503
- http://www.securitytracker.com/id/1041294
- https://bugs.debian.org/873383
- https://eprint.iacr.org/2017/806
- https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=da780c8183cccc8f533c8ace8211ac2cb2bdee7b
- https://lists.debian.org/debian-security-announce/2017/msg00221.html
- https://security.netapp.com/advisory/ntap-20180726-0002/
- https://security-tracker.debian.org/tracker/CVE-2017-0379
- https://www.debian.org/security/2017/dsa-3959
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
Related Security Bulletins
- Information disclosure in GNU Libgcrypt
- Information disclosure in libgcrypt (Alpine package)
- Arch Linux update for lib32-libgcrypt
- Arch Linux update for libgcrypt
- Slackware Linux update for libgcrypt
- Fedora 27 update for libgcrypt
- Fedora 26 update for libgcrypt
- Fedora 25 update for libgcrypt
- Multiple vulnerabilities in Oracle Communications WebRTC Session Controller