First published: Tue Jan 28 2020(Updated: )
USN-4236-1 fixed a vulnerability in Libgcrypt. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: It was discovered that Libgcrypt was susceptible to a ECDSA timing attack. An attacker could possibly use this attack to recover sensitive information.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libgcrypt11 | <1.5.3-2ubuntu4.6+esm1 | 1.5.3-2ubuntu4.6+esm1 |
=14.04 | ||
All of | ||
ubuntu/libgcrypt11 | <1.5.0-3ubuntu0.9 | 1.5.0-3ubuntu0.9 |
=12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this advisory is USN-4236-3.
The title of this advisory is 'USN-4236-3: Libgcrypt vulnerability'.
The affected software is Libgcrypt version 1.5.3-2ubuntu4.6+esm1 on Ubuntu 12.04 ESM and Libgcrypt version 1.5.0-3ubuntu0.9 on Ubuntu 14.04.
The fix for this vulnerability is to update Libgcrypt to version 1.5.3-2ubuntu4.6+esm1 on Ubuntu 12.04 ESM and version 1.5.0-3ubuntu0.9 on Ubuntu 14.04.
You can find more information about this vulnerability at the following references: 1) [CVE-2019-13627](https://ubuntu.com/security/CVE-2019-13627), 2) [USN-4236-2](https://ubuntu.com/security/notices/USN-4236-2), 3) [USN-4236-1](https://ubuntu.com/security/notices/USN-4236-1).