CVE-2019-13627

Name
CVE-2019-13627
Description
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Third Party Advisory https://github.com/gpg/libgcrypt/releases/tag/libgcrypt-1.8.5
Third Party Advisory http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00060.html
Third Party Advisory https://security-tracker.debian.org/tracker/CVE-2019-13627
Mailing List https://lists.debian.org/debian-lts-announce/2019/09/msg00024.html
Mailing List http://www.openwall.com/lists/oss-security/2019/10/02/2
Third Party Advisory https://minerva.crocs.fi.muni.cz/
Third Party Advisory https://lists.debian.org/debian-lts-announce/2020/01/msg00001.html
Third Party Advisory https://usn.ubuntu.com/4236-1/
Third Party Advisory http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00018.html
Third Party Advisory https://usn.ubuntu.com/4236-2/
Third Party Advisory https://usn.ubuntu.com/4236-3/
Third Party Advisory https://security.gentoo.org/glsa/202003-32

Match rules

CPE URI Source package Min version Max version
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:* ubuntu_linux == None == 12.04
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:* ubuntu_linux == None == 14.04
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* ubuntu_linux == None == 16.04
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* ubuntu_linux == None == 18.04
cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:* ubuntu_linux == None == 19.04
cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:* ubuntu_linux == None == 19.10
cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:* leap == None == 15.0
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* leap == None == 15.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libgcrypt 3.10-main 1.8.5-r0 Natanael Copa <ncopa@alpinelinux.org> fixed