Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576.
{ "binaries": [ { "binary_name": "gnupg", "binary_version": "1.4.16-1ubuntu2.1" }, { "binary_name": "gnupg-curl", "binary_version": "1.4.16-1ubuntu2.1" }, { "binary_name": "gnupg-udeb", "binary_version": "1.4.16-1ubuntu2.1" }, { "binary_name": "gpgv", "binary_version": "1.4.16-1ubuntu2.1" }, { "binary_name": "gpgv-udeb", "binary_version": "1.4.16-1ubuntu2.1" } ], "availability": "No subscription required", "ubuntu_priority": "medium" }
{ "binaries": [ { "binary_name": "libgcrypt11", "binary_version": "1.5.3-2ubuntu4.1" }, { "binary_name": "libgcrypt11-dbg", "binary_version": "1.5.3-2ubuntu4.1" }, { "binary_name": "libgcrypt11-dev", "binary_version": "1.5.3-2ubuntu4.1" }, { "binary_name": "libgcrypt11-doc", "binary_version": "1.5.3-2ubuntu4.1" }, { "binary_name": "libgcrypt11-udeb", "binary_version": "1.5.3-2ubuntu4.1" } ], "availability": "No subscription required", "ubuntu_priority": "medium" }
{ "binaries": [ { "binary_name": "libgcrypt20", "binary_version": "1.6.1-2ubuntu1" }, { "binary_name": "libgcrypt20-dbg", "binary_version": "1.6.1-2ubuntu1" }, { "binary_name": "libgcrypt20-dev", "binary_version": "1.6.1-2ubuntu1" }, { "binary_name": "libgcrypt20-doc", "binary_version": "1.6.1-2ubuntu1" } ], "availability": "No subscription required", "ubuntu_priority": "medium" }