Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.4.16-1ubuntu2.1", "binary_name": "gnupg" }, { "binary_version": "1.4.16-1ubuntu2.1", "binary_name": "gnupg-curl" }, { "binary_version": "1.4.16-1ubuntu2.1", "binary_name": "gnupg-udeb" }, { "binary_version": "1.4.16-1ubuntu2.1", "binary_name": "gpgv" }, { "binary_version": "1.4.16-1ubuntu2.1", "binary_name": "gpgv-udeb" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.5.3-2ubuntu4.1", "binary_name": "libgcrypt11" }, { "binary_version": "1.5.3-2ubuntu4.1", "binary_name": "libgcrypt11-dbg" }, { "binary_version": "1.5.3-2ubuntu4.1", "binary_name": "libgcrypt11-dev" }, { "binary_version": "1.5.3-2ubuntu4.1", "binary_name": "libgcrypt11-doc" }, { "binary_version": "1.5.3-2ubuntu4.1", "binary_name": "libgcrypt11-udeb" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.6.1-2ubuntu1", "binary_name": "libgcrypt20" }, { "binary_version": "1.6.1-2ubuntu1", "binary_name": "libgcrypt20-dbg" }, { "binary_version": "1.6.1-2ubuntu1", "binary_name": "libgcrypt20-dev" }, { "binary_version": "1.6.1-2ubuntu1", "binary_name": "libgcrypt20-doc" } ] }