CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:L/AC:M/Au:N/C:P/I:N/A:N
EPSS
Percentile
5.3%
Werner Koch of the GNU project reports:
Noteworthy changes in version 1.5.3:
Mitigate the Yarom/Falkner flush+reload side-channel attack on RSA secret keys…
Note that Libgcrypt is used by GnuPG 2.x and thus this release fixes the above
problem. The fix for GnuPG less than 2.0 can be found in the just released GnuPG
1.4.14.