Libgcrypt up to 1.8.7/1.9.2 ElGamal Encryption timing discrepancy

A vulnerability classified as problematic has been found in Libgcrypt up to 1.8.7/1.9.2. Affected is some unknown functionality of the component ElGamal Encryption. Upgrading to version 1.8.8 or 1.9.3 eliminates this vulnerability. Applying a patch is able to eliminate this problem. The bugfix is ready for download at dev.gnupg.org. The best possible mitigation is suggested to be upgrading to the latest version.

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2024-35141 : IBM SECURITY VERIFY ACCESS DOCKER UP TO 10.0.6 UNNECESSARY PRIVILEGES

CVE-2024-35141 : IBM SECURITY VERIFY ACCESS DOCKER UP TO 10.0.6 UNNECESSARY PRIVILEGES

Description IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to

CVE-2023-23356 : QNAP QUFIREWALL UP TO 2.3.2 COMMAND INJECTION

CVE-2023-23356 : QNAP QUFIREWALL UP TO 2.3.2 COMMAND INJECTION

Description A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could

CVE-2024-48889 : FORTINET FORTIMANAGER UP TO 6.4.14/7.0.12/7.2.7/7.4.4/7.6.0 FGFM REQUEST OS COMMAND INJECTION

CVE-2024-48889 : FORTINET FORTIMANAGER UP TO 6.4.14/7.0.12/7.2.7/7.4.4/7.6.0 FGFM REQUEST OS COMMAND INJECTION

Description An Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) vulnerability [CWE-78] in FortiManager version