[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Netscape Security Services, Libgcrypt - (bulletinjul2018)

ID: oval:org.secpod.oval:def:2103205Date: (C)2020-01-14   (M)2023-12-07
Class: PATCHFamily: unix




Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

Platform:
Sun Solaris 11
Product:
system/mozilla-nss
system/library/security/libgcrypt
system/library/mozilla-nss
system/library/mozilla-nss/header-nss
security/pinentry
security/pinentry-gtk
security/nss-utilities
library/security/nss
library/security/libksba
library/security/libgpg-error
library/security/libassuan
library/security/gpgme
library/pth
library/nspr/header-nspr
library/npth
library/java/jss
library/java/commons-logging
library/java/apache-commons-logging
library/gmime
crypto/gnupg
consolidation/sic_team/sic_team-incorporation
SUNWtlsu
SUNWtlsd
SUNWtls
SUNWprd
SUNWpr
SUNWjss
SUNWaclg
Reference:
bulletinjul2018
CVE-2018-0495
CVE-2017-5461
CVE-2017-7805
CVE    3
CVE-2017-7805
CVE-2017-5461
CVE-2018-0495
CPE    1
cpe:/o:oracle:solaris:11

© SecPod Technologies