CVE-2021-33560

Source
https://cve.org/CVERecord?id=CVE-2021-33560
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-33560.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-33560
Downstream
ALPINE (1)
BELL (1)
CLSA (1)
DEBIAN (1)
JLSEC (1)
MGASA (1)
OESA (1)
openSUSE (3)
RHSA (1)
RLSA (1)
ROOT (1)
SUSE (4)
UBUNTU (1)
Related
Published
2021-06-08T11:15:07Z
Modified
2026-07-08T06:00:39Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.

Database specific
{
    "unresolved_ranges":  [
        {
            "cpes":  [
                "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "9.0"
                },
                {
                    "last_affected":  "9.0"
                }
            ],
            "source":  "CPE_STRING",
            "vendor_product":  "debian:debian_linux"
        },
        {
            "cpes":  [
                "cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*",
                "cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "33"
                },
                {
                    "last_affected":  "33"
                },
                {
                    "introduced":  "34"
                },
                {
                    "last_affected":  "34"
                }
            ],
            "source":  "CPE_STRING",
            "vendor_product":  "fedoraproject:fedora"
        },
        {
            "cpes":  [
                "cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:1.11.0:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "1.11.0"
                },
                {
                    "last_affected":  "1.11.0"
                }
            ],
            "source":  "CPE_STRING",
            "vendor_product":  "oracle:communications_cloud_native_core_binding_support_function"
        },
        {
            "cpes":  [
                "cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.10.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.9.0:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "1.9.0"
                },
                {
                    "last_affected":  "1.9.0"
                },
                {
                    "introduced":  "1.10.0"
                },
                {
                    "last_affected":  "1.10.0"
                }
            ],
            "source":  "CPE_STRING",
            "vendor_product":  "oracle:communications_cloud_native_core_network_function_cloud_native_environment"
        },
        {
            "cpes":  [
                "cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.14.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.1:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "1.14.0"
                },
                {
                    "last_affected":  "1.14.0"
                },
                {
                    "introduced":  "1.15.0"
                },
                {
                    "last_affected":  "1.15.0"
                },
                {
                    "introduced":  "1.15.1"
                },
                {
                    "last_affected":  "1.15.1"
                }
            ],
            "source":  "CPE_STRING",
            "vendor_product":  "oracle:communications_cloud_native_core_network_repository_function"
        },
        {
            "cpes":  [
                "cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.8.0:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "1.8.0"
                },
                {
                    "last_affected":  "1.8.0"
                }
            ],
            "source":  "CPE_STRING",
            "vendor_product":  "oracle:communications_cloud_native_core_network_slice_selection_function"
        },
        {
            "cpes":  [
                "cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:1.15.0:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "1.15.0"
                },
                {
                    "last_affected":  "1.15.0"
                }
            ],
            "source":  "CPE_STRING",
            "vendor_product":  "oracle:communications_cloud_native_core_service_communication_proxy"
        }
    ]
}
References

Affected packages

Git / git.gnupg.org/libgcrypt.git

Affected ranges

Type
GIT
Repo
git://git.gnupg.org/libgcrypt.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:gnupg:libgcrypt:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "1.8.8"
        },
        {
            "introduced":  "1.9.0"
        },
        {
            "fixed":  "1.9.3"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

Other
DEVEL-BRANCH-1-1
V-0-2-8
V0-0-0
V0-1-0
V0-2-0
V0-2-10
V0-2-15
V0-2-17
V0-2-18
V0-2-19
V0-2-6
V0-3-0
V0-3-1
V0-3-2
V0-3-3
V0-3-4
V0-3-5
V0-4-0
V0-4-1
V0-4-2
V0-4-3
V0-4-4
V0-4-5
V0-9-0
V0-9-1
V0-9-10
V0-9-11
V0-9-2
V0-9-3
V0-9-4
V0-9-5
V0-9-6
V0-9-7
V0-9-8
V0-9-9
V1-0-0
V1-0-1
V1-0-1-ePit-1
V1-0-2
V1-0-3
V1-0-4
V1-1-0
V1-1-10
V1-1-11
V1-1-12
V1-1-2
V1-1-3
V1-1-4
V1-1-42
V1-1-43
V1-1-44
V1-1-5
V1-1-6
V1-1-7
V1-1-8
V1-1-9
V1-1-90
V1-1-91
V1-1-92
V1-1-93
V1-1-94
V1-2-0
V1-2-1
ecc-integration-done
last-gpl-version
marcus-after-thread-cbs
marcus-before-thread-cbs
now-less-freedom-protected
post-nuke-of-trailing-ws
libgcrypt-1.*
libgcrypt-1.3.0
libgcrypt-1.3.1
libgcrypt-1.3.2
libgcrypt-1.4.0
libgcrypt-1.4.1
libgcrypt-1.4.1rc1
libgcrypt-1.4.2
libgcrypt-1.4.2rc1
libgcrypt-1.4.2rc2
libgcrypt-1.4.3
libgcrypt-1.4.4
libgcrypt-1.5.0
libgcrypt-1.5.0-beta1
libgcrypt-1.6.0
libgcrypt-1.7.0
libgcrypt-1.7.1
libgcrypt-1.7.2
libgcrypt-1.7.3
libgcrypt-1.8.0
libgcrypt-1.8.1
libgcrypt-1.8.2
libgcrypt-1.8.3
libgcrypt-1.8.4
libgcrypt-1.8.5
libgcrypt-1.8.6
libgcrypt-1.8.7
libgcrypt-1.9-base
libgcrypt-1.9.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-33560.json"

Git / github.com/gpg/libgcrypt

Affected ranges

Type
GIT
Repo
https://github.com/gpg/libgcrypt
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:gnupg:libgcrypt:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "1.8.8"
        },
        {
            "introduced":  "1.9.0"
        },
        {
            "fixed":  "1.9.3"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

Other
DEVEL-BRANCH-1-1
V-0-2-8
V0-0-0
V0-1-0
V0-2-0
V0-2-10
V0-2-15
V0-2-17
V0-2-18
V0-2-19
V0-2-6
V0-3-0
V0-3-1
V0-3-2
V0-3-3
V0-3-4
V0-3-5
V0-4-0
V0-4-1
V0-4-2
V0-4-3
V0-4-4
V0-4-5
V0-9-0
V0-9-1
V0-9-10
V0-9-11
V0-9-2
V0-9-3
V0-9-4
V0-9-5
V0-9-6
V0-9-7
V0-9-8
V0-9-9
V1-0-0
V1-0-1
V1-0-1-ePit-1
V1-0-2
V1-0-3
V1-0-4
V1-1-0
V1-1-10
V1-1-11
V1-1-12
V1-1-2
V1-1-3
V1-1-4
V1-1-42
V1-1-43
V1-1-44
V1-1-5
V1-1-6
V1-1-7
V1-1-8
V1-1-9
V1-1-90
V1-1-91
V1-1-92
V1-1-93
V1-1-94
V1-2-0
V1-2-1
ecc-integration-done
last-gpl-version
marcus-after-thread-cbs
marcus-before-thread-cbs
now-less-freedom-protected
post-nuke-of-trailing-ws
libgcrypt-1.*
libgcrypt-1.3.0
libgcrypt-1.3.1
libgcrypt-1.3.2
libgcrypt-1.4.0
libgcrypt-1.4.1
libgcrypt-1.4.1rc1
libgcrypt-1.4.2
libgcrypt-1.4.2rc1
libgcrypt-1.4.2rc2
libgcrypt-1.4.3
libgcrypt-1.4.4
libgcrypt-1.5.0
libgcrypt-1.5.0-beta1
libgcrypt-1.6.0
libgcrypt-1.7.0
libgcrypt-1.7.1
libgcrypt-1.7.2
libgcrypt-1.7.3
libgcrypt-1.8.0
libgcrypt-1.8.1
libgcrypt-1.8.2
libgcrypt-1.8.3
libgcrypt-1.8.4
libgcrypt-1.8.5
libgcrypt-1.8.6
libgcrypt-1.8.7
libgcrypt-1.9-base
libgcrypt-1.9.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-33560.json"