LOW · 2.1

CVE-2014-5270

Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers t...

Vulnerability Description

Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
GnupgLibgcrypt<= 1.5.3
DebianDebian Linux7.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-5270?

CVE-2014-5270 is a vulnerability with a CVSS score of 2.1 (LOW). Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers t...

How severe is CVE-2014-5270?

CVE-2014-5270 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-5270?

Check the references section above for vendor advisories and patch information. Affected products include: Gnupg Libgcrypt, Debian Debian Linux.