CVE-2019-13627
25.09.2019, 15:15
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.Enginsight
Vendor | Product | Version |
---|---|---|
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 18.04 |
canonical | ubuntu_linux | 19.04 |
canonical | ubuntu_linux | 19.10 |
opensuse | leap | 15.0 |
opensuse | leap | 15.1 |
libgcrypt20_project | libgcrypt20 | 1.6.3-2\+deb8u4 |
libgcrypt20_project | libgcrypt20 | 1.7.6-2\+deb9u3 |
libgcrypt20_project | libgcrypt20 | 1.8.4-5 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References