First published: Sun Aug 27 2017(Updated: )
Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.c.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libgcrypt20 | <=1.8.0-1<=1.7.1-1 | 1.8.1-1 1.7.9-1 1.7.6-2+deb9u2 |
debian/libgcrypt20 | 1.8.7-6 1.10.1-3 1.11.0-2 1.11.0-5 | |
Libgcrypt | <=1.8.0 | |
Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-0379 is considered to have a medium severity level due to its potential impact on the confidentiality of secret keys.
To fix CVE-2017-0379, upgrade Libgcrypt to version 1.8.1 or later.
CVE-2017-0379 affects versions of Libgcrypt prior to 1.8.1 and Debian Linux 9.0 installations.
CVE-2017-0379 relates to side-channel attacks on Curve25519 implementations.
CVE-2017-0379 can potentially allow attackers to more easily discover secret keys used in cryptographic operations.