Lucene search

K
redhatcveRedhat.comRH:CVE-2019-13627
HistoryOct 22, 2019 - 7:50 a.m.

CVE-2019-13627

2019-10-2207:50:55
redhat.com
access.redhat.com
10

EPSS

0.003

Percentile

72.1%

A timing attack was found in the way ECCDSA was implemented in libgcrypt. A man-in-the-middle attacker could use this attack during signature generation to recover the private key. This attack is only feasible when the attacker is local to the machine where the signature is being generated. Attacks over the network or via the internet are not feasible.