First published: Mon Jan 13 2020(Updated: )
It was discovered that Libgcrypt was susceptible to a ECDSA timing attack. An attacker could possibly use this attack to recover sensitive information.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libgcrypt20 | <1.8.4-5ubuntu2.1 | 1.8.4-5ubuntu2.1 |
=19.10 | ||
All of | ||
ubuntu/libgcrypt20 | <1.8.4-3ubuntu1.1 | 1.8.4-3ubuntu1.1 |
=19.04 | ||
All of | ||
ubuntu/libgcrypt20 | <1.8.1-4ubuntu1.2 | 1.8.1-4ubuntu1.2 |
=18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Libgcrypt vulnerability is CVE-2019-13627.
The Libgcrypt vulnerability is susceptible to an ECDSA timing attack which could allow an attacker to recover sensitive information.
The Libgcrypt vulnerability affects the libgcrypt20 package.
To fix the Libgcrypt vulnerability, you need to update the libgcrypt20 package to version 1.8.4-5ubuntu2.1 (for Ubuntu 19.10), 1.8.4-3ubuntu1.1 (for Ubuntu 19.04), or 1.8.1-4ubuntu1.2 (for Ubuntu 18.04).
You can find more information about the Libgcrypt vulnerability in the following references: [USN-4236-2](https://ubuntu.com/security/notices/USN-4236-2) and [USN-4236-3](https://ubuntu.com/security/notices/USN-4236-3).