CVE-2014-5270
10.10.2014, 01:55
Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576.Enginsight
Vendor | Product | Version |
---|---|---|
gnupg | libgcrypt | 𝑥 ≤ 1.5.3 |
gnupg | libgcrypt | 1.4.0 |
gnupg | libgcrypt | 1.4.3 |
gnupg | libgcrypt | 1.4.4 |
gnupg | libgcrypt | 1.4.5 |
gnupg | libgcrypt | 1.4.6 |
gnupg | libgcrypt | 1.5.0 |
gnupg | libgcrypt | 1.5.1 |
gnupg | libgcrypt | 1.5.2 |
debian | debian_linux | 7.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References