[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256148

 
 

909

 
 

199106

 
 

282

Paid content will be excluded from the download.


Download | Alert*


oval:org.secpod.oval:def:21801
The host is installed with libgcrypt before 1.5.4 and is prone to an unspecified vulnerability. A flaw is present in the application, which does not properly perform ciphertext normalization and ciphertext randomizations. Successful exploitation makes it easier for physically proximate attackers to ...

oval:org.secpod.oval:def:601837
Daniel Genkin, Itamar Pipman and Eran Tromer discovered that Elgamal encryption subkeys in applications using the libgcrypt11 library, for example GnuPG 2.x, could be leaked via a side-channel attack.

oval:org.secpod.oval:def:52288
libgcrypt11: LGPL Crypto library Libgcrypt could expose sensitive information when performing decryption.

oval:org.secpod.oval:def:601773
Genkin, Pipman and Tromer discovered a side-channel attack on Elgamal encryption subkeys . In addition, this update hardens GnuPG"s behaviour when treating keyserver responses; GnuPG now filters keyserver responses to only accepts those keyid"s actually requested by the user.

oval:org.secpod.oval:def:702188
gnupg: GNU privacy guard - a free PGP replacement GnuPG could expose sensitive information when performing decryption.

oval:org.secpod.oval:def:702187
libgcrypt11: LGPL Crypto library Libgcrypt could expose sensitive information when performing decryption.

oval:org.secpod.oval:def:702488
gnupg: GNU privacy guard - a free PGP replacement - gnupg2: GNU privacy guard - a free PGP replacement Several security issues were fixed in GnuPG.

oval:org.secpod.oval:def:52442
gnupg: GNU privacy guard - a free PGP replacement - gnupg2: GNU privacy guard - a free PGP replacement Several security issues were fixed in GnuPG.

oval:org.secpod.oval:def:1200057
Fix a side-channel attack on data-dependent timing variations in modular exponentiation, which can potentially lead to an information leak. Fix a side-channel attack which can potentially lead to an information leak. Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perf ...

CPE    9
cpe:/o:debian:debian_linux:7.0
cpe:/a:gnupg:libgcrypt:1.4.0
cpe:/a:gnupg:libgcrypt:1.5.0
cpe:/a:gnupg:libgcrypt:1.5.1
...
CWE    1
CWE-200
*CVE
CVE-2014-5270

© SecPod Technologies