CVE-2014-3591
CVE-2014-3591
| Published Date | 2019-11-29 |
|---|---|
| Product | centos |
| Severity | Medium (4.2) |
| Component | libgcrypt |
| Affected Versions | CentOS 7 |
| Patched Versions | libgcrypt-1.5.3-14_ol002.el7 |
CVE Details
OL CVE Issue Summary:
Libgcrypt before 1.6.3 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by using crafted ciphertext -- a side-channel attack that can lead to information disclosure.