Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GnuPG libgcrypt RSA 密钥信息泄露漏洞
Vulnerability Description
GnuPG(GNU Privacy Guard)是GNU计划开发的一套开源的加密软件,采用GNU通用公共许可证,并支持公钥、对称加密、散列等算法。libgcrypt是其中的一个通用加密库。 GnuPG 1.4.13及之前版本,GnuPG 2.0.x版本及其他产品中使用的Libgcrypt 1.5.2及之前版本中存在漏洞。本地攻击者可通过跨频道攻击(side-channel attack)利用该漏洞获取PSA密钥信息。
CVSS Information
N/A
Vulnerability Type
N/A