UBUNTU-CVE-2017-7526
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-7526
UBUNTU-CVE-2017-7526
Summary:
Details: libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method for computing the sliding-window expansion. The same attack is believed to work on RSA-2048 with moderately more computation. This side-channel requires that attacker can run arbitrary software on the hardware where the private RSA key is used.
References: https://ubuntu.com/security/CVE-2017-7526, https://eprint.iacr.org/2017/627, https://ubuntu.com/security/notices/USN-3347-1, https://ubuntu.com/security/notices/USN-3347-2, https://ubuntu.com/security/notices/USN-3733-1, https://ubuntu.com/security/notices/USN-3733-2, https://www.cve.org/CVERecord?id=CVE-2017-7526
Affected packages
Package
Name: gnupg
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
