VulnerabilityModified
CVE-2013-4242
GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.
LOW 1.9EPSS 0.53%
Does this matter?
Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.
Description
GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.
- CVSS 2.0
- 1.9 LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 0.53% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- canonical/ubuntu linux · debian/debian linux · gnupg/gnupg · gnupg/libgcrypt · opensuse/opensuse
- Source
- secalert@redhat.com
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=717880
- http://eprint.iacr.org/2013/448
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
- http://lists.gnupg.org/pipermail/gnupg-announce/2013q3/000330.html
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00003.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1457.html
- http://secunia.com/advisories/54318Vendor Advisory
- http://secunia.com/advisories/54321Vendor Advisory
- http://secunia.com/advisories/54332Vendor Advisory
- http://secunia.com/advisories/54375Vendor Advisory
- http://www.debian.org/security/2013/dsa-2730
- http://www.debian.org/security/2013/dsa-2731
- http://www.kb.cert.org/vuls/id/976534US Government Resource
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/bid/61464
- http://www.ubuntu.com/usn/USN-1923-1Vendor Advisory
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=717880
- http://eprint.iacr.org/2013/448
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
- http://lists.gnupg.org/pipermail/gnupg-announce/2013q3/000330.html
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00003.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1457.html
- http://secunia.com/advisories/54318Vendor Advisory
- http://secunia.com/advisories/54321Vendor Advisory
- http://secunia.com/advisories/54332Vendor Advisory
- http://secunia.com/advisories/54375Vendor Advisory
- http://www.debian.org/security/2013/dsa-2730
- http://www.debian.org/security/2013/dsa-2731
- http://www.kb.cert.org/vuls/id/976534US Government Resource
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.