CVE-2024-2236

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.
Configurations

No configuration.

History

21 Nov 2024, 09:09

Type Values Removed Values Added
References
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2268268 -
References () https://access.redhat.com/security/cve/CVE-2024-2236 - () https://access.redhat.com/security/cve/CVE-2024-2236 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=2245218 - () https://bugzilla.redhat.com/show_bug.cgi?id=2245218 -

12 Nov 2024, 18:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:9404 -

14 Sep 2024, 04:15

Type Values Removed Values Added
References
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=2268268', 'source': 'secalert@redhat.com'}

25 Apr 2024, 17:15

Type Values Removed Values Added
References
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2245218 -
Summary
  • (es) Se encontró una falla de canal lateral basada en sincronización en la implementación RSA de libgcrypt. Este problema puede permitir que un atacante remoto inicie un ataque estilo Bleichenbacher, que puede conducir al descifrado de textos cifrados RSA.

06 Mar 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-06 22:15

Updated : 2024-11-21 09:09


NVD link : CVE-2024-2236

Mitre link : CVE-2024-2236

CVE.ORG link : CVE-2024-2236


JSON object : View

Products Affected

No product.

CWE
CWE-208

Observable Timing Discrepancy