update: libgcrypt #1388
Labels
advisory/upstream-blocked
blocked by upstream projects
advisory
security advisory
cvss/MEDIUM
>= 4 && < 7 assessed CVSS
security
security concerns
Name: libgcrypt
CVEs: CVE-2024-2236
CVSSs: 5.9
Action Needed: TBD
Summary: A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.
See also https://bugzilla.redhat.com/show_bug.cgi?id=2268268.
refmap.gentoo: TBD
The text was updated successfully, but these errors were encountered: