Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2021-06-08 04:15
Updated : 2022-12-06 17:20
NVD link : CVE-2021-33560
Mitre link : CVE-2021-33560
JSON object : View
CWE
CWE-203
Observable Discrepancy
Products Affected
oracle
- communications_cloud_native_core_service_communication_proxy
- communications_cloud_native_core_network_repository_function
- communications_cloud_native_core_network_function_cloud_native_environment
- communications_cloud_native_core_binding_support_function
- communications_cloud_native_core_network_slice_selection_function
gnupg
- libgcrypt
fedoraproject
- fedora
debian
- debian_linux