In Libgcrypt before 1.7.7, an attacker who learns the EdDSA session key (from side-channel observation during the signing process) can easily recover the long-term secret key. 1.7.7 makes a cipher/ecc-eddsa.c change to store this session key in secure memory, to ensure that constant-time point operations are used in the MPI library.
CVSS Details
- CVSS 3.0 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libgcrypt | Aug 30, 2017 | Jun 10, 2017 |
| Debian | — | Upgrade libgcrypt20 | Jun 15, 2017 | Jun 10, 2017 |
| Oracle Solaris | — | Upgrade system/library/security/libgcrypt to version 1.7.9-0.175.3.27.0.4.0 on Solaris 11.3 | Dec 19, 2017 | Jun 10, 2017 |
| Suse | — | Upgrade libgcrypt20-32bitUpgrade libgcrypt-develUpgrade libgcrypt20-hmac-32bitUpgrade libgcrypt20Upgrade libgcrypt20-hmac | Jun 19, 2017 | Jun 10, 2017 |
| Ubuntu | — | Upgrade libgcrypt20 | Jul 4, 2017 | Jun 10, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 11, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub