« List of all CVEs

CVE-2015-0837

Published: 11/29/2019 Last updated: 8/6/2024 Reserved: 1/7/2015

The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."

CNA assigner: debian (79363d38-fa19-49d1-9214-5f28da3f3ac5) Requested by: n/a

Opam packages affected (1)

0install

Products affected (2)

Product Vendor Version
Libgcrypt GNU unspecified
GnuPG GNU 6.0.2.11

References (10)