CLSA-2023-1698945053
Dashboard / Vulnerabilities / CLSA-2023-1698945053
CLSA-2023-1698945053
Published: 2 Nov 2023Last Modified: 1 Jun 2026
Upstream:
Summary: libgcrypt: Fix of 4 CVEs
Details: - CVE-2013-4576: Normalize the MPIs to prevent possible side-channel attacks - CVE-2014-3591: Use ciphertext blinding for Elgamal to prevent possible side-channel attacks - CVE-2021-33560: Use of smaller K for ephemeral key in ElGamal prevent generation of weak keys - CVE-2021-40528: Add exponent blinding as well to mitigate side-channel attack on mpi_powm - tests: Add a benchmark for Elgamal
Affected packages
Package
Name: libgcrypt
Purl: pkg:rpm/tuxcare/libgcrypt?distro=centos-7
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -1.5.3-14.el7.tuxcare.els1
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
