Information disclosure in Libgcrypt - CVE-2015-7511

 

Information disclosure in Libgcrypt - CVE-2015-7511

Published: April 20, 2016 / Updated: July 28, 2020


Vulnerability identifier: #VU32337
CSH Severity: Low
CVSS v4: 1 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-7511
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local non-authenticated attacker to gain access to sensitive information.

Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations.


Affected software

Libgcrypt
libgcrypt (Alpine package)
libgcrypt
Slackware Linux
Fedora
IBM Tivoli Storage Manager

How to mitigate CVE-2015-7511

Install update from vendor's website.

Libgcrypt - update to 1.6.5
libgcrypt (Alpine package) - update to 1.6.5-r0
libgcrypt - update to 1.5.5
libgcrypt - addressed in versions 1.6.5-1.fc23, 1.6.5-1.fc24
IBM Tivoli Storage Manager - update to 5.4.3.0

External References

Related Security Bulletins