Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576.
{ "binaries": [ { "binary_name": "libgcrypt11", "binary_version": "1.5.3-2ubuntu4.1" }, { "binary_name": "libgcrypt11-dbg", "binary_version": "1.5.3-2ubuntu4.1" }, { "binary_name": "libgcrypt11-dev", "binary_version": "1.5.3-2ubuntu4.1" }, { "binary_name": "libgcrypt11-doc", "binary_version": "1.5.3-2ubuntu4.1" }, { "binary_name": "libgcrypt11-udeb", "binary_version": "1.5.3-2ubuntu4.1" } ], "availability": "No subscription required" }