Side-channel attack in Libgcrypt - CVE-2017-7526
Published: June 30, 2017 / Updated: June 30, 2017
Vulnerability identifier: #VU7276
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7526
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists in libgcrypt's RSA-1024 implementation using left-to-right method for computing the sliding-window expansion. A remote attacker can perform side-channel attack and gain access to potentially sensitive information.
The vulnerability exists in libgcrypt's RSA-1024 implementation using left-to-right method for computing the sliding-window expansion. A remote attacker can perform side-channel attack and gain access to potentially sensitive information.
Affected software
Libgcrypt
Debian Linux
Arch Linux
Ubuntu
Slackware Linux
Fedora
libgcrypt (Alpine package)
libgcrypt
Debian Linux
Arch Linux
Ubuntu
Slackware Linux
Fedora
libgcrypt (Alpine package)
libgcrypt
How to mitigate CVE-2017-7526
Update libgcrypt to version 1.7.8.
libgcrypt (Alpine package) - update to 1.7.8-r0
libgcrypt - addressed in versions 1.7.8-1.fc24, 1.7.8-1.fc25, 1.7.8-1.fc26
libgcrypt - addressed in versions 1.7.8-1.fc24, 1.7.8-1.fc25, 1.7.8-1.fc26
External References
Related Security Bulletins
- Side-channel attack in Libcrypt
- Slackware Linux update for libgcrypt
- Debian update for libgcrypt20
- Arch Linux update for libgcrypt
- Ubuntu update for Libgcrypt
- Ubuntu update for Libgcrypt
- Debian update for gnupg
- Side-channel attack in libgcrypt (Alpine package)
- Fedora 25 update for libgcrypt
- Fedora 24 update for libgcrypt
- Fedora 26 update for libgcrypt