CVE-2014-3591
Last modified
CVE-2014-3591 is a medium-severity vulnerability rated 4.2/10 on the CVSS scale. Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using crafted ciphertext and the fluctuations in the electromagnetic field during multiplication.. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using crafted ciphertext and the fluctuations in the electromagnetic field during multiplication.
Metrics
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnupg | Gnupg | < 1.4.19 |
| Gnupg | Libgcrypt | < 1.6.3 |
| Debian | Debian Linux | 7.0 |
| Debian | Debian Linux | 8.0 |
References
- http://www.cs.tau.ac.il/~tromer/radioexp/Third Party Advisory
- http://www.debian.org/security/2015/dsa-3184Third Party Advisory
- http://www.debian.org/security/2015/dsa-3185Third Party Advisory
- https://lists.gnupg.org/pipermail/gnupg-announce/2015q1/000363.htmlPatch, Release Notes, Vendor Advisory
- https://lists.gnupg.org/pipermail/gnupg-announce/2015q1/000364.htmlPatch, Vendor Advisory
- http://www.cs.tau.ac.il/~tromer/radioexp/Third Party Advisory
- http://www.debian.org/security/2015/dsa-3184Third Party Advisory
- http://www.debian.org/security/2015/dsa-3185Third Party Advisory
- https://lists.gnupg.org/pipermail/gnupg-announce/2015q1/000363.htmlPatch, Release Notes, Vendor Advisory
- https://lists.gnupg.org/pipermail/gnupg-announce/2015q1/000364.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-3591?
How severe is CVE-2014-3591?
How do I fix CVE-2014-3591?
Are you affected by CVE-2014-3591?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
