CVE-2015-7511 describes a vulnerability in Libgcrypt versions prior to 1.6.5, affecting various Canonical, Debian, and GnuPG products. This flaw involves improper elliptic-point curve multiplication during decryption, which could allow physically proximate attackers to extract ECDH keys. The vulnerability has a low severity CVSS score of 2.0, requiring physical access and high attack complexity, with a potential impact of information disclosure. There is no evidence of active exploitation, no public exploit code available, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.6.4CPE matchmatch criteria | cpe:2.3:a:gnupg:libgcrypt:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations.
Apr 12, 2016libgcrypt: side-channel attack on ECDH with Weierstrass curves
Feb 8, 2016