Back

MEDIUM

libgcrypt: use ciphertext blinding for Elgamal decryption (new side-channel attack)

Published Nov 29, 2019

Description

Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using crafted ciphertext and the fluctuations in the electromagnetic field during multiplication.

Affected products

Remediation

Red Hat mitigation

In order to successfully exploit this flaw the attacker needs to following conditions: 1. They need to be very close to the system, in order to record the fluctuations in the electromagnetic waves being emitted by the system. 2. The attacker needs to send specially-crafted cipher text to the system for decryption. 3. The attacker needs to record the electromagnetic fluctuations when these cipher texts are being decrypted. The above conditions can be true only when a laptop is being used for decryption in an unsafe external environment. Typical server setups may not be vulnerable.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 29, 2019
Updated Aug 6, 2024
Reserved May 14, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Feb 27, 2015