CVE-2013-4242
Publication date 29 July 2013
Last updated 24 July 2024
Ubuntu priority
GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.
Status
Package | Ubuntu Release | Status |
---|---|---|
gnupg | ||
libgcrypt11 | ||
Patch details
Package | Patch details |
---|---|
gnupg | |
libgcrypt11 |
References
Related Ubuntu Security Notices (USN)
- USN-1923-1
- GnuPG, Libgcrypt vulnerability
- 1 August 2013