Record summary

CVE-2015-0837 has a selected CVSS score of 5.9 (medium).

Description

The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."

Description source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE Listbefore 1.4.19affected
CVE Listbefore 1.6.3affected

References

6