yocto ▾
›
master ▾
›
component
›
libgcrypt
Component Overview
Vulnerability Overview
Name
libgcrypt
Version
1.12.2
Type
library
Description
General purpose cryptographic library based on the code from GnuPG
Licenses
BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later
PURL
-
CPE
cpe:2.3:*:gnupg:libgcrypt:1.12.2:*:*:*:*:*:*:*
Other Versions
#
Project
Branch
Version
yocto
kirkstone
1.9.4
yocto
scarthgap
1.10.4
Vulnerabilities
#
Name
Analysis
Description
CVE-2024-2236
Exploitable
A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.