Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.
References
| Link | Resource |
|---|---|
| https://dev.gnupg.org/T5466 | Release Notes Vendor Advisory |
| https://dev.gnupg.org/rCe8b7f10be275bcedb5fc05ed4837a89bfd605c61 | Patch Vendor Advisory |
| https://dev.gnupg.org/T5305 | Release Notes Vendor Advisory |
| https://dev.gnupg.org/T5328 | Vendor Advisory |
| https://lists.debian.org/debian-lts-announce/2021/06/msg00021.html | Mailing List Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R7OAPCUGPF3VLA7QAJUQSL255D4ITVTL/ | Mailing List Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BKKTOIGFW2SGN3DO2UHHVZ7MJSYN4AAB/ | Mailing List Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuoct2021.html | Third Party Advisory |
| https://www.oracle.com/security-alerts/cpujan2022.html | Patch Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuapr2022.html | Patch Third Party Advisory |
| https://www.oracle.com/security-alerts/cpujul2022.html |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2021-06-08 11:15
Updated : 2022-07-25 18:15
NVD link : CVE-2021-33560
Mitre link : CVE-2021-33560
JSON object : View
Products Affected
debian
- debian_linux
fedoraproject
- fedora
gnupg
- libgcrypt
oracle
- communications_cloud_native_core_binding_support_function
- communications_cloud_native_core_service_communication_proxy
- communications_cloud_native_core_network_slice_selection_function
- communications_cloud_native_core_network_function_cloud_native_environment
- communications_cloud_native_core_network_repository_function
CWE
CWE-203
Observable Discrepancy
