CVE-2021-33560

Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.
References
Link Resource
https://dev.gnupg.org/T5305 Release Notes Vendor Advisory
https://dev.gnupg.org/T5328 Vendor Advisory
https://dev.gnupg.org/T5466 Release Notes Vendor Advisory
https://dev.gnupg.org/rCe8b7f10be275bcedb5fc05ed4837a89bfd605c61 Patch Vendor Advisory
https://lists.debian.org/debian-lts-announce/2021/06/msg00021.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BKKTOIGFW2SGN3DO2UHHVZ7MJSYN4AAB/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7OAPCUGPF3VLA7QAJUQSL255D4ITVTL/
https://security.gentoo.org/glsa/202210-13 Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html Third Party Advisory
https://dev.gnupg.org/T5305 Release Notes Vendor Advisory
https://dev.gnupg.org/T5328 Vendor Advisory
https://dev.gnupg.org/T5466 Release Notes Vendor Advisory
https://dev.gnupg.org/rCe8b7f10be275bcedb5fc05ed4837a89bfd605c61 Patch Vendor Advisory
https://lists.debian.org/debian-lts-announce/2021/06/msg00021.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BKKTOIGFW2SGN3DO2UHHVZ7MJSYN4AAB/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7OAPCUGPF3VLA7QAJUQSL255D4ITVTL/
https://security.gentoo.org/glsa/202210-13 Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnupg:libgcrypt:*:*:*:*:*:*:*:*
cpe:2.3:a:gnupg:libgcrypt:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:1.11.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.9.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.10.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.14.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.8.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:1.15.0:*:*:*:*:*:*:*

History

21 Nov 2024, 06:09

Type Values Removed Values Added
References () https://dev.gnupg.org/T5305 - Release Notes, Vendor Advisory () https://dev.gnupg.org/T5305 - Release Notes, Vendor Advisory
References () https://dev.gnupg.org/T5328 - Vendor Advisory () https://dev.gnupg.org/T5328 - Vendor Advisory
References () https://dev.gnupg.org/T5466 - Release Notes, Vendor Advisory () https://dev.gnupg.org/T5466 - Release Notes, Vendor Advisory
References () https://dev.gnupg.org/rCe8b7f10be275bcedb5fc05ed4837a89bfd605c61 - Patch, Vendor Advisory () https://dev.gnupg.org/rCe8b7f10be275bcedb5fc05ed4837a89bfd605c61 - Patch, Vendor Advisory
References () https://lists.debian.org/debian-lts-announce/2021/06/msg00021.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2021/06/msg00021.html - Mailing List, Third Party Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BKKTOIGFW2SGN3DO2UHHVZ7MJSYN4AAB/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BKKTOIGFW2SGN3DO2UHHVZ7MJSYN4AAB/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7OAPCUGPF3VLA7QAJUQSL255D4ITVTL/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7OAPCUGPF3VLA7QAJUQSL255D4ITVTL/ -
References () https://security.gentoo.org/glsa/202210-13 - Third Party Advisory () https://security.gentoo.org/glsa/202210-13 - Third Party Advisory
References () https://www.oracle.com/security-alerts/cpuapr2022.html - Patch, Third Party Advisory () https://www.oracle.com/security-alerts/cpuapr2022.html - Patch, Third Party Advisory
References () https://www.oracle.com/security-alerts/cpujan2022.html - Patch, Third Party Advisory () https://www.oracle.com/security-alerts/cpujan2022.html - Patch, Third Party Advisory
References () https://www.oracle.com/security-alerts/cpujul2022.html - Patch, Third Party Advisory () https://www.oracle.com/security-alerts/cpujul2022.html - Patch, Third Party Advisory
References () https://www.oracle.com/security-alerts/cpuoct2021.html - Third Party Advisory () https://www.oracle.com/security-alerts/cpuoct2021.html - Third Party Advisory

07 Nov 2023, 03:35

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BKKTOIGFW2SGN3DO2UHHVZ7MJSYN4AAB/', 'name': 'FEDORA-2021-31fdc84207', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R7OAPCUGPF3VLA7QAJUQSL255D4ITVTL/', 'name': 'FEDORA-2021-24d4e06195', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'FEDORA'}
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BKKTOIGFW2SGN3DO2UHHVZ7MJSYN4AAB/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7OAPCUGPF3VLA7QAJUQSL255D4ITVTL/ -

Information

Published : 2021-06-08 11:15

Updated : 2024-11-21 06:09


NVD link : CVE-2021-33560

Mitre link : CVE-2021-33560

CVE.ORG link : CVE-2021-33560


JSON object : View

Products Affected

oracle

  • communications_cloud_native_core_network_repository_function
  • communications_cloud_native_core_network_function_cloud_native_environment
  • communications_cloud_native_core_network_slice_selection_function
  • communications_cloud_native_core_service_communication_proxy
  • communications_cloud_native_core_binding_support_function

gnupg

  • libgcrypt

debian

  • debian_linux

fedoraproject

  • fedora
CWE
CWE-203

Observable Discrepancy