Information disclosure in Libgcrypt - CVE-2013-4242

 

Information disclosure in Libgcrypt - CVE-2013-4242

Published: August 20, 2013 / Updated: July 28, 2020


Vulnerability identifier: #VU32638
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2013-4242
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: GNU
Affected software:
Libgcrypt

Detailed vulnerability description

The vulnerability allows a local non-authenticated attacker to gain access to sensitive information.

GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.


How to mitigate CVE-2013-4242

Install update from vendor's website.

Sources