Related Vulnerabilities: CVE-2021-33560  

A weakness has been found in the generation of ephemeral keys in the ElGamal encryption of libgcrypt when the recipient's key is not generated using the same or a compatible implementation.

Severity Medium

Remote Yes

Type Private key recovery

Description

A weakness has been found in the generation of ephemeral keys in the ElGamal encryption of libgcrypt when the recipient's key is not generated using the same or a compatible implementation.

AVG-2014 lib32-libgcrypt15 1.5.6-5 Medium Vulnerable

AVG-2013 libgcrypt15 1.5.6-4 Medium Vulnerable

AVG-2012 lib32-libgcrypt 1.9.3-1 Medium Vulnerable

AVG-2011 libgcrypt 1.9.3-1 Medium Vulnerable

https://dev.gnupg.org/T5328
https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commitdiff;h=3462280f2e23e16adf3ed5176e0f2413d8861320