UBUNTU-CVE-2014-5270
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-5270
UBUNTU-CVE-2014-5270
Summary:
Details: Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576.
References: https://ubuntu.com/security/CVE-2014-5270, http://lists.gnupg.org/pipermail/gnupg-announce/2014q3/000352.html, https://ubuntu.com/security/notices/USN-2339-2, https://ubuntu.com/security/notices/USN-2339-1, https://www.cve.org/CVERecord?id=CVE-2014-5270, https://ubuntu.com/security/notices/USN-2554-1
Affected packages
Package
Name: libgcrypt11
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
