CVE-2015-7511
19.04.2016, 21:59
Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations.Enginsight
| Vendor | Product | Version |
|---|---|---|
| gnupg | libgcrypt | 𝑥 ≤ 1.6.4 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 15.10 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libgcrypt11 |
| ||||||||||||||||||||
| libgcrypt20 |
|
Common Weakness Enumeration
References