Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian DSA-3184-1 Critical: GnuPG DoS And Side-Channel Risks

debian
Calendar Grey March 12, 2015
Debian Logo
To address GnuPG vulnerabilities in Debian DSA-3184-1, update packages, enhance security configurations, enforce access controls, and monitor activities effectively
Multiple vulnerabilities were discovered in GnuPG, the GNU Privacy Guard: CVE-2014-3591

Summary

CVE-2014-3591

The Elgamal decryption routine was susceptible to a side-channel
attack discovered by researchers of Tel Aviv University. Ciphertext
blinding was enabled to counteract it. Note that this may have a
quite noticeable impact on Elgamal decryption performance.

CVE-2015-0837

The modular exponentiation routine mpi_powm() was susceptible to a
side-channel attack caused by data-dependent timing variations when
accessing its internal pre-computed table.

CVE-2015-1606

The keyring parsing code did not properly reject certain packet
types not belonging in a keyring, which caused an access to memory
already freed. This could allow remote attackers to cause a denial
of service (crash) via crafted keyring files.

For the stable distribution (wheezy), these problems have been fixed in
version 1.4.12-7+deb7u7.

For the upcoming stable distribution (jessie), these problems have been
fixed in version 1.4.18-7.

For the unstable distribution (sid), these problems ha...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: gnupg
CVE ID: CVE-2014-3591 CVE-2015-0837 CVE-2015-1606

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here