Information disclosure in Libgcrypt - CVE-2014-5270
Published: October 10, 2014 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a local non-authenticated attacker to gain access to sensitive information.
Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576.
Affected software
Amazon Linux AMI
Gentoo Linux
libgcrypt (Alpine package)
How to mitigate CVE-2014-5270
libgcrypt (Alpine package) - update to 1.5.4-r0