CVE-2014-5270
Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the…
Does this matter?
Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.
Description
Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.53% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- gnupg/libgcrypt · debian/debian linux
- Source
- cve@mitre.org
References
- http://lists.gnupg.org/pipermail/gnupg-announce/2014q3/000352.htmlPatch, Vendor Advisory
- http://openwall.com/lists/oss-security/2014/08/16/2Mailing List, Third Party Advisory
- http://www.cs.tau.ac.il/~tromer/handsoff/Technical Description
- http://www.debian.org/security/2014/dsa-3024
- http://www.debian.org/security/2014/dsa-3073Third Party Advisory
- http://lists.gnupg.org/pipermail/gnupg-announce/2014q3/000352.htmlPatch, Vendor Advisory
- http://openwall.com/lists/oss-security/2014/08/16/2Mailing List, Third Party Advisory
- http://www.cs.tau.ac.il/~tromer/handsoff/Technical Description
- http://www.debian.org/security/2014/dsa-3024
- http://www.debian.org/security/2014/dsa-3073Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.