First published: Wed Sep 25 2019(Updated: )
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/libgcrypt11 | <1.5.3-2ubuntu4.6+ | 1.5.3-2ubuntu4.6+ |
ubuntu/libgcrypt20 | <1.8.1-4ubuntu1.2 | 1.8.1-4ubuntu1.2 |
ubuntu/libgcrypt20 | <1.8.4-3ubuntu1.1 | 1.8.4-3ubuntu1.1 |
ubuntu/libgcrypt20 | <1.8.4-5ubuntu2.1 | 1.8.4-5ubuntu2.1 |
ubuntu/libgcrypt20 | <1.8.5-1 | 1.8.5-1 |
ubuntu/libgcrypt20 | <1.6.5-2ubuntu0.6 | 1.6.5-2ubuntu0.6 |
debian/libgcrypt20 | 1.8.7-6 1.10.1-3 1.11.0-6 | |
Ubuntu Linux | =12.04 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =19.04 | |
Ubuntu Linux | =19.10 | |
openSUSE | =15.0 | |
openSUSE | =15.1 | |
All of | ||
GNU Libgcrypt | =1.6.3-2\+deb8u4 | |
Debian Debian Linux | =8.0 | |
All of | ||
GNU Libgcrypt | =1.7.6-2\+deb9u3 | |
Debian Debian Linux | =9.0 | |
All of | ||
GNU Libgcrypt | =1.8.4-5 | |
Debian Debian Linux | =10.0 | |
GNU Libgcrypt | =1.6.3-2\+deb8u4 | |
Debian Debian Linux | =8.0 | |
GNU Libgcrypt | =1.7.6-2\+deb9u3 | |
Debian Debian Linux | =9.0 | |
GNU Libgcrypt | =1.8.4-5 | |
Debian Debian Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13627 refers to a ECDSA timing attack vulnerability in the libgcrypt20 cryptographic library.
CVE-2019-13627 has a severity value of 6.3, which is considered medium.
Versions 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4 of libgcrypt20 are affected by CVE-2019-13627.
To fix CVE-2019-13627, update to version 1.8.5-2 or 1.6.3-2+deb8u7 of libgcrypt20.
You can find more information about CVE-2019-13627 at the following references: [Link 1](https://github.com/gpg/libgcrypt/releases/tag/libgcrypt-1.8.5), [Link 2](https://security-tracker.debian.org/tracker/CVE-2019-13627), [Link 3](https://lists.debian.org/debian-lts-announce/2019/09/msg00024.html).