CVE-2019-13627: Medium severity Canonical Ubuntu Linux vulnerability
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-13627?
CVE-2019-13627 refers to a ECDSA timing attack vulnerability in the libgcrypt20 cryptographic library.
How severe is CVE-2019-13627?
CVE-2019-13627 has a severity value of 6.3, which is considered medium.
Which versions of libgcrypt20 are affected by CVE-2019-13627?
Versions 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4 of libgcrypt20 are affected by CVE-2019-13627.
How can I fix CVE-2019-13627?
To fix CVE-2019-13627, update to version 1.8.5-2 or 1.6.3-2+deb8u7 of libgcrypt20.
Where can I find more information about CVE-2019-13627?
You can find more information about CVE-2019-13627 at the following references: [Link 1](https://github.com/gpg/libgcrypt/releases/tag/libgcrypt-1.8.5), [Link 2](https://security-tracker.debian.org/tracker/CVE-2019-13627), [Link 3](https://lists.debian.org/debian-lts-announce/2019/09/msg00024.html).