Information disclosure in Libgcrypt - CVE-2015-7511
Published: April 20, 2016 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a local non-authenticated attacker to gain access to sensitive information.
Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations.
Affected software
libgcrypt (Alpine package)
libgcrypt
Slackware Linux
Fedora
IBM Tivoli Storage Manager
How to mitigate CVE-2015-7511
libgcrypt (Alpine package) - update to 1.6.5-r0
libgcrypt - update to 1.5.5
libgcrypt - addressed in versions 1.6.5-1.fc23, 1.6.5-1.fc24
IBM Tivoli Storage Manager - update to 5.4.3.0
External References
- http://lists.opensuse.org/opensuse-updates/2016-05/msg00027.html
- http://www.cs.tau.ac.IL/~tromer/ecdh/
- http://www.debian.org/security/2016/dsa-3474
- http://www.debian.org/security/2016/dsa-3478
- http://www.securityfocus.com/bid/83253
- http://www.ubuntu.com/usn/USN-2896-1
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W2IL4PAEICHGA2XMQYRY3MIWHM4GMPAG/
- https://lists.gnupg.org/pipermail/gnupg-announce/2016q1/000384.html
- https://security.gentoo.org/glsa/201610-04