ZeroHour

CVE-2018-0495

PoC
CVSS 3.0
4.7 medium
EPSS
<1%p57
Published
()
Modified
Description

Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

Vendors
gnupgcanonicaldebianredhatoracle
Products
libgcrypt, ubuntu linux, debian linux, ansible tower, enterprise linux desktop, enterprise linux server, enterprise linux workstation, traffic director
Weakness
CWE-203
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.