Information disclosure in Libgcrypt - CVE-2013-4242

 

Information disclosure in Libgcrypt - CVE-2013-4242

Published: August 20, 2013 / Updated: July 28, 2020


Vulnerability identifier: #VU32638
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-4242
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local non-authenticated attacker to gain access to sensitive information.

GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.


Affected software

Libgcrypt
Amazon Linux AMI
Gentoo Linux
Slackware Linux
libgcrypt (Alpine package)
gnupg
dev-libs/libgcrypt
libgcrypt
libgpg-error
app-crypt/gnupg

How to mitigate CVE-2013-4242

Install update from vendor's website.

Libgcrypt - update to 1.5.3
libgcrypt (Alpine package) - update to 1.5.3-r0
gnupg - update to 1.4.14
dev-libs/libgcrypt - update to 1.5.3
libgcrypt - update to 1.5.3
libgpg-error - update to 1.11
app-crypt/gnupg - update to 2.0.22

External References

Related Security Bulletins