Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2017-7526

Published: July 26, 2018Last modified: November 9, 2023

Description

libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method for computing the sliding-window expansion. The same attack is believed to work on RSA-2048 with moderately more computation. This side-channel requires that attacker can run arbitrary software on the hardware where the private RSA key is used.

Severity score breakdown

ParameterValue
Base score6.8
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeCHANGED
ConfidentialityHIGH
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSgnupgNot affected (2.2.40-r0)
libgcryptNot affected (1.10.1-r0)
StreamgnupgNot affected (2.4.3-r1)
libgcryptNot affected (1.10.2-r2)

References

ON THIS PAGE