TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2014-3591

MEDIUM
4.2

Beschreibung

Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using crafted ciphertext and the fluctuations in the electromagnetic field during multiplication.

CVE Details

CVSS v3.1 Bewertung4.2
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
AngriffsvektorPHYSICAL
KomplexitatHIGH
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht11/29/2019
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

debian:debian_linuxgnupg:gnupggnupg:libgcrypt

Schwachen (CWE)

CWE-200

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.