CVE-2013-4242

Public on 2013-08-19
Modified on 2014-09-16
Description
GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.
Severity
Medium severity
Medium
CVSS v3 Base Score
1.9
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 gnupg 2013-09-19 ALAS-2013-225 Fixed
Amazon Linux 1 libgcrypt 2013-09-19 ALAS-2013-226 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv2 1.9 AV:L/AC:M/Au:N/C:P/I:N/A:N
NVD CVSSv2 1.9 AV:L/AC:M/Au:N/C:P/I:N/A:N