2.6
CVSSv2

CVE-2019-13627

Published: 25/09/2019 Updated: 21/07/2021
CVSS v2 Base Score: 2.6 | Impact Score: 4.9 | Exploitability Score: 1.9
CVSS v3 Base Score: 6.3 | Impact Score: 5.2 | Exploitability Score: 1
VMScore: 231
Vector: AV:L/AC:H/Au:N/C:P/I:P/A:N

Vulnerability Summary

It exists that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 19.04

canonical ubuntu linux 19.10

opensuse leap 15.0

opensuse leap 15.1

libgcrypt20_project libgcrypt20 1.6.3-2\\+deb8u4

libgcrypt20_project libgcrypt20 1.7.6-2\\+deb9u3

libgcrypt20_project libgcrypt20 1.8.4-5

Vendor Advisories

Debian Bug report logs - #938938 libgcrypt20: CVE-2019-13627 Package: src:libgcrypt20; Maintainer for src:libgcrypt20 is Debian GnuTLS Maintainers <pkg-gnutls-maint@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 30 Aug 2019 13:03:01 UTC Severity: important Tags: security, u ...
Libgcrypt could be made to expose sensitive information ...
Libgcrypt could be made to expose sensitive information ...
Libgcrypt could be made to expose sensitive information ...
Synopsis Moderate: Release of OpenShift Serverless 1110 Type/Severity Security Advisory: Moderate Topic Release of OpenShift Serverless 1110 Description Red Hat OpenShift Serverless 1110 is a generally available release of theOpenShift Serverless Operator This version of the OpenShif ...
Synopsis Moderate: OpenShift Container Platform 46 compliance-operator security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for compliance-content-container, ose-compliance-openscap-container, ose-compliance-operator-container, and ose-compliance-operator-metadata-container ...
Synopsis Moderate: Release of OpenShift Serverless 1120 Type/Severity Security Advisory: Moderate Topic Release of OpenShift Serverless 1120Red Hat Product Security has rated this update as having a security impactof Moderate A Common Vulnerability Scoring System (CVSS) base score,which gives a detaile ...
Synopsis Moderate: libgcrypt security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for libgcrypt is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scorin ...
Synopsis Moderate: Red Hat Quay v333 bug fix and security update Type/Severity Security Advisory: Moderate Topic Red Hat Quay v333 is now available with bug fixes and security updatesRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring S ...
Synopsis Moderate: OpenShift Container Platform 46 compliance-operator security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for compliance-content-container, ose-compliance-openscap-container, ose-compliance-operator-container, and ose-compliance-operator-metadata-container ...
Synopsis Moderate: OpenShift Container Platform 4103 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4103 is now available withupdates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impact of ...
Synopsis Moderate: Red Hat OpenShift Container Storage 460 security, bug fix, enhancement update Type/Severity Security Advisory: Moderate Topic Updated images are now available for Red Hat OpenShift Container Storage 460 on Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as ha ...
Synopsis Important: Service Telemetry Framework 14 security update Type/Severity Security Advisory: Important Topic An update is now available for Service Telemetry Framework 14 for RHEL 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which g ...
A vulnerability has been found in the ECDSA/EdDSA implementation of libgcrypt up to 184, allowing for practical recovery of the long-term private key ...

Github Repositories

on GitLab CI

Practice of Handolint: DL3026 DL3003 SC2164 Normally, vulnerability scanner clair could be set to the threshold 'Medium' and in the current example there will be: cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2019-13627 cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2019-18197 This exposures are solved by updating the version of nginx, FROM quayio/jiteso