4.7

CVE-2018-0495

Exploit

Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GnupgLibgcrypt Version < 1.7.10
GnupgLibgcrypt Version >= 1.8.0 < 1.8.3
CanonicalUbuntu Linux Version12.04 SwEditionesm
CanonicalUbuntu Linux Version14.04 SwEditionlts
CanonicalUbuntu Linux Version16.04 SwEditionlts
CanonicalUbuntu Linux Version17.10
CanonicalUbuntu Linux Version18.04 SwEditionlts
CanonicalUbuntu Linux Version18.10
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
RedhatAnsible Tower Version3.3
OracleTraffic Director Version11.1.1.9.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.46
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.7 1 3.6
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 1.9 3.4 2.9
AV:L/AC:M/Au:N/C:P/I:N/A:N
CWE-203 Observable Discrepancy

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.

https://usn.ubuntu.com/3692-2/
Third Party Advisory
https://usn.ubuntu.com/3692-1/
Third Party Advisory
http://www.securitytracker.com/id/1041144
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1041147
Third Party Advisory
VDB Entry
https://dev.gnupg.org/T4011
Patch
Vendor Advisory
https://usn.ubuntu.com/3689-1/
Third Party Advisory
https://usn.ubuntu.com/3689-2/
Third Party Advisory
https://usn.ubuntu.com/3850-1/
Third Party Advisory
https://usn.ubuntu.com/3850-2/
Third Party Advisory