An issue has been found in libgcrypt20, a crypto library. Mishandling of ElGamal encryption results in a possible side-channel attack and an interoperability problem with keys not generated by . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2691-1
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. For Debian 8 "Jessie", this issue has been fixed in libgcrypt20 version . Package : libgcrypt20 Version : 1.6.3-2+deb8u6 CVE ID : CVE-2019-13627 Debian Bug : #938938 It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. For Debian 8 "Jessie", this issue has been fixed in libgcrypt20 version 1.6.3-2+deb8u6. We recommend that you upgrade your libgcrypt20 packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
Felix Doerre and Vladimir Klebanov from the Karlsruhe Institute of Technology discovered a flaw in the mixing functions of Libgcrypt's random number generator. An attacker who obtains 4640 bits from the RNG can trivially predict the next 160 bits of output. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3650-1
Daniel Genkin, Lev Pachmanov, Itamar Pipman and Eran Tromer discovered that the ECDH secret decryption keys in applications using the libgcrypt20 library could be leaked via a side-channel attack. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3474-1
Get the latest Linux and open source security news straight to your inbox.