Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576.
{ "binaries": [ { "binary_version": "1.5.3-2ubuntu4.1", "binary_name": "libgcrypt11" }, { "binary_version": "1.5.3-2ubuntu4.1", "binary_name": "libgcrypt11-dbg" }, { "binary_version": "1.5.3-2ubuntu4.1", "binary_name": "libgcrypt11-dev" }, { "binary_version": "1.5.3-2ubuntu4.1", "binary_name": "libgcrypt11-doc" }, { "binary_version": "1.5.3-2ubuntu4.1", "binary_name": "libgcrypt11-udeb" } ], "availability": "No subscription required" }