CVE-2013-4242
Last modified
CVE-2013-4242 is a vulnerability of currently unknown severity. GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Ubuntu Linux | 10.04 |
| Canonical | Ubuntu Linux | 12.04 |
| Canonical | Ubuntu Linux | 12.10 |
| Canonical | Ubuntu Linux | 13.04 |
| Debian | Debian Linux | 6.0 |
| Debian | Debian Linux | 7.0 |
| Gnupg | Gnupg | <= 1.4.13 |
| Gnupg | Gnupg | 0.0.0 |
| Gnupg | Gnupg | 0.2.15 |
| Gnupg | Gnupg | 0.2.16 |
| Gnupg | Gnupg | 0.2.17 |
| Gnupg | Gnupg | 0.2.18 |
| Gnupg | Gnupg | 0.2.19 |
| Gnupg | Gnupg | 0.3.0 |
| Gnupg | Gnupg | 0.3.1 |
| Gnupg | Gnupg | 0.3.2 |
| Gnupg | Gnupg | 0.3.3 |
| Gnupg | Gnupg | 0.3.4 |
| Gnupg | Gnupg | 0.3.5 |
| Gnupg | Gnupg | 0.4.0 |
| Gnupg | Gnupg | 0.4.1 |
| Gnupg | Gnupg | 0.4.3 |
| Gnupg | Gnupg | 0.4.4 |
| Gnupg | Gnupg | 0.4.5 |
| Gnupg | Gnupg | 0.9.0 |
| Gnupg | Gnupg | 0.9.1 |
| Gnupg | Gnupg | 0.9.2 |
| Gnupg | Gnupg | 0.9.3 |
| Gnupg | Gnupg | 0.9.4 |
| Gnupg | Gnupg | 0.9.5 |
| Gnupg | Gnupg | 0.9.6 |
| Gnupg | Gnupg | 0.9.7 |
| Gnupg | Gnupg | 0.9.8 |
| Gnupg | Gnupg | 0.9.9 |
| Gnupg | Gnupg | 0.9.10 |
| Gnupg | Gnupg | 0.9.11 |
| Gnupg | Gnupg | 1.0.0 |
| Gnupg | Gnupg | 1.0.1 |
| Gnupg | Gnupg | 1.0.2 |
| Gnupg | Gnupg | 1.0.3 |
| Gnupg | Gnupg | 1.0.4 |
| Gnupg | Gnupg | 1.0.5 |
| Gnupg | Gnupg | 1.0.6 |
| Gnupg | Gnupg | 1.0.7 |
| Gnupg | Gnupg | 1.2.0 |
| Gnupg | Gnupg | 1.2.1 |
| Gnupg | Gnupg | 1.2.2 |
| Gnupg | Gnupg | 1.2.3 |
| Gnupg | Gnupg | 1.2.4 |
| Gnupg | Gnupg | 1.2.5 |
Showing 50 of 93 affected configurations. See NVD for the full list.
References
- http://secunia.com/advisories/54318Vendor Advisory
- http://secunia.com/advisories/54321Vendor Advisory
- http://secunia.com/advisories/54332Vendor Advisory
- http://secunia.com/advisories/54375Vendor Advisory
- http://www.kb.cert.org/vuls/id/976534US Government Resource
- http://www.ubuntu.com/usn/USN-1923-1Vendor Advisory
- http://secunia.com/advisories/54318Vendor Advisory
- http://secunia.com/advisories/54321Vendor Advisory
- http://secunia.com/advisories/54332Vendor Advisory
- http://secunia.com/advisories/54375Vendor Advisory
- http://www.kb.cert.org/vuls/id/976534US Government Resource
- http://www.ubuntu.com/usn/USN-1923-1Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-4242?
How severe is CVE-2013-4242?
How do I fix CVE-2013-4242?
Are you affected by CVE-2013-4242?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
