Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.881858
Categoría:CentOS Local Security Checks
Título:CentOS Update for gnupg CESA-2014:0016 centos5
Resumen:The remote host is missing an update for the 'gnupg'; package(s) announced via the referenced advisory.
Descripción:Summary:
The remote host is missing an update for the 'gnupg'
package(s) announced via the referenced advisory.

Vulnerability Insight:
The GNU Privacy Guard (GnuPG or GPG) is a tool for encrypting data and
creating digital signatures, compliant with the proposed OpenPGP Internet
standard and the S/MIME standard.

It was found that GnuPG was vulnerable to side-channel attacks via acoustic
cryptanalysis. An attacker in close range to a target system that is
decrypting ciphertexts could possibly use this flaw to recover the RSA
secret key from that system. (CVE-2013-4576)

Red Hat would like to thank Werner Koch of GnuPG upstream for reporting
this issue. Upstream acknowledges Genkin, Shamir, and Tromer as the
original reporters.

All gnupg users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.

Affected Software/OS:
gnupg on CentOS 5

Solution:
Please install the updated packages.

CVSS Score:
2.1

CVSS Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2013-4576
BugTraq ID: 64424
http://www.securityfocus.com/bid/64424
Debian Security Information: DSA-2821 (Google Search)
http://www.debian.org/security/2013/dsa-2821
http://www.cs.tau.ac.il/~tromer/acoustic/
http://www.tau.ac.il/~tromer/papers/acoustic-20131218.pdf
http://lists.gnupg.org/pipermail/gnupg-devel/2013-December/028102.html
http://seclists.org/oss-sec/2013/q4/520
http://seclists.org/oss-sec/2013/q4/523
http://osvdb.org/101170
RedHat Security Advisories: RHSA-2014:0016
http://rhn.redhat.com/errata/RHSA-2014-0016.html
http://www.securitytracker.com/id/1029513
http://www.ubuntu.com/usn/USN-2059-1
XForce ISS Database: gunpg-cve20134576-info-disclosure(89846)
https://exchange.xforce.ibmcloud.com/vulnerabilities/89846
CopyrightCopyright (C) 2014 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.