Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Genkin, Pipman and Tromer discovered a side-channel attack on Elgamal encryption subkeys (CVE-2014-5270). In addition, this update hardens GnuPG's behaviour when treating . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3024-1
A vulnerability in Libgcrypt could allow a remote attacker to extract ElGamal private key information.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201408-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Libgcrypt: Side-channel attack Date: August 29, 2014 Bugs: #519396 ID: 201408-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in Libgcrypt could allow a remote attacker to extract ElGamal private key information. Background ========= Libgcrypt is a general purpose cryptographic library derived out of GnuPG. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-libs/libgcrypt < 1.5.4 > = 1.5.4 Description ========== A vulnerability in the implementation of ElGamal decryption procedures of Libgcrypt leaks information to various side-channels. Impact ===== A physical side-channel attack allows a remote attacker to fully extract decryption keys during the decryption of a chosen ciphertext. Workaround ========= There is no known workaround at this time. Resolution ========= All Libgcrypt users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/libgcrypt-1.5.4" References ========= [ 1 ] CVE-2014-5270 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-5270 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201408-10 Concerns? ======== Security is a primary focusof Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.