CVE-2013-4576

Description

GnuPG 1.x before 1.4.16 generates RSA keys using sequences of introductions with certain patterns that introduce a side channel, which allows physically proximate attackers to extract RSA keys via a chosen-ciphertext attack and acoustic cryptanalysis during decryption. NOTE: applications are not typically expected to protect themselves from acoustic side-channel attacks, since this is arguably the responsibility of the physical device. Accordingly, issues of this type would not normally receive a CVE identifier. However, for this issue, the developer has specified a security policy in which GnuPG should offer side-channel resistance, and developer-specified security-policy violations are within the scope of CVE.

Risk Information

Base Score
7.4
MODERATE
Vector
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
0.108

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.0Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.3Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.4Windows
Vulnerabilities CVE-2006-6169,CVE-2013-4576 are affected in GnuPG for windows 1.4Windows
Vulnerabilities CVE-2007-1263,CVE-2013-4351,CVE-2013-4576 are affected in GnuPG for windows 1.4.6Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.8Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.10Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.11Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.12Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.2Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.5Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.0.0Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.0.1Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.0.2Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.0.3Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.0.6Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.0.7Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.2.0Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.2.1Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.2.2Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.2.3Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.2.4Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.2.5Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.2.6Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.2.7Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.3.0Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.3.1Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.3.2Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.3.3Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.3.4Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.3.6Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.3.90Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.3.91Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.3.92Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.3.93Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.13Windows
Vulnerabilities CVE-2013-4402,CVE-2013-4576,CVE-2014-4617,CVE-2016-6313 are affected in GnuPG for windows 1.4.14Windows
Vulnerabilities CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.4.15Windows
(RHSA-2014:0016) Moderate: gnupg security update gnupg-1.4.5-18.el5_10.1.i386.rpmLinux
(RHSA-2014:0016) Moderate: gnupg security update gnupg-1.4.5-18.el5_10.1.x86_64.rpmLinux
CVE-2013-4576NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234