CVE-2015-0837: Debian Linux
Medium severity, CVSS 5.9. EPSS: 2% chance of exploitation in the next 30 days.
The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."
Affected products
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Gnupg Gnupg: before 1.4.19 (fixed in 1.4.19)
- Gnupg Libgcrypt: before 1.6.3 (fixed in 1.6.3)
Published 2019-11-29. Last modified 2026-06-17.