ZeroHour

CVE-2021-33560

CVSS 3.1
7.5 high
EPSS
2%p83
Published
()
Modified
Description

Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.

Vendors
gnupgdebianfedoraprojectoracle
Products
libgcrypt, debian linux, fedora, communications cloud native core binding support function, communications cloud native core network function cloud native environment, communications cloud native core network repository function, communications cloud native core network slice selection function, communications cloud native core service communication proxy
Weakness
CWE-203, CWE-325
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.