CVE-2014-5270 (debian_linux, libgcrypt)

CVE-2014-5270 (debian_linux, libgcrypt)

Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576.

Source: CVE-2014-5270 (debian_linux, libgcrypt)

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다