Oracle Linux 5 / 6 : libgcrypt (ELSA-2013-1457)

low Nessus Plugin ID 70596

Synopsis

The remote Oracle Linux host is missing one or more security updates.

Description

From Red Hat Security Advisory 2013:1457 :

An updated libgcrypt package that fixes one security issue is now available for Red Hat Enterprise Linux 5 and 6.

The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section.

The libgcrypt library provides general-purpose implementations of various cryptographic algorithms.

It was found that GnuPG was vulnerable to the Yarom/Falkner flush+reload cache side-channel attack on the RSA secret exponent. An attacker able to execute a process on the logical CPU that shared the L3 cache with the GnuPG process (such as a different local user or a user of a KVM guest running on the same host with the kernel same-page merging functionality enabled) could possibly use this flaw to obtain portions of the RSA secret key. (CVE-2013-4242)

All libgcrypt users are advised to upgrade to this updated package, which contains a backported patch to correct this issue.

Solution

Update the affected libgcrypt packages.

See Also

https://oss.oracle.com/pipermail/el-errata/2013-October/003759.html

https://oss.oracle.com/pipermail/el-errata/2013-October/003760.html

Plugin Details

Severity: Low

ID: 70596

File Name: oraclelinux_ELSA-2013-1457.nasl

Version: 1.11

Type: local

Agent: unix

Published: 10/25/2013

Updated: 1/14/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.7

CVSS v2

Risk Factor: Low

Base Score: 1.9

Temporal Score: 1.4

Vector: CVSS2#AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: p-cpe:/a:oracle:linux:libgcrypt, p-cpe:/a:oracle:linux:libgcrypt-devel, cpe:/o:oracle:linux:5, cpe:/o:oracle:linux:6

Required KB Items: Host/local_checks_enabled, Host/OracleLinux, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 10/24/2013

Vulnerability Publication Date: 8/19/2013

Reference Information

CVE: CVE-2013-4242

BID: 61464

RHSA: 2013:1457