Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 1923-1 Moderate: GnuPG And Libgcrypt Information Leak Threat

ubuntu
Calendar Grey August 1, 2013
Scroller Ubuntu
Debian Security Advisory DSA-4983-1 outlines a vulnerability regarding OpenSSL and libcrypto impacting various distributions.
GnuPG and Libgcrypt could be made to expose sensitive information.

Summary

GnuPG and Libgcrypt could be made to expose sensitive information.

Software Description:

- gnupg: GNU privacy guard - a free PGP replacement

- libgcrypt11: LGPL Crypto library - runtime library

Details:

Yuval Yarom and Katrina Falkner discovered a timing-based information leak,

known as Flush+Reload, that could be used to trace execution in programs.

GnuPG and Libgcrypt followed different execution paths based on key-related

data, which could be used to expose the contents of private keys.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
  gnupg                           1.4.12-7ubuntu1.1
  libgcrypt11                     1.5.0-3ubuntu2.2

Ubuntu 12.10:
  gnupg                           1.4.11-3ubuntu4.2
  libgcrypt11                     1.5.0-3ubuntu1.1

Ubuntu 12.04 LTS:
  gnupg                           1.4.11-3ubuntu2.3
  libgcrypt11                     1.5.0-3ubuntu0.2

Ubuntu 10.04 LTS:
  gnupg                           1.4.10-2ubuntu1.3
  libgcrypt11                     1.4.4-5ubuntu2.2

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1923-1

CVE-2013-4242

August 01, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.