CVE-2013-4576 describes a side-channel vulnerability in GnuPG 1.x before 1.4.16, where specific RSA key generation patterns allow physically proximate attackers to extract RSA keys through acoustic cryptanalysis during decryption. This vulnerability has a low CVSS score of 2.1, indicating a local attack vector with low complexity and a potential impact of partial confidentiality loss. While not typically assigned a CVE for acoustic side-channels, GnuPG's developer policy for side-channel resistance warranted its inclusion. There is no evidence of active exploitation, nor is public exploit code available, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.4.15CPE matchmatch criteria | cpe:2.3:a:gnupg:gnupg:*:*:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:gnupg:gnupg:1.0.0:*:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:a:gnupg:gnupg:1.0.1:*:*:*:*:*:*:* | ||
1.0.2CPE matchmatch criteria | cpe:2.3:a:gnupg:gnupg:1.0.2:*:*:*:*:*:*:* | ||
1.0.3CPE matchmatch criteria | cpe:2.3:a:gnupg:gnupg:1.0.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.