CVE-2015-0837: Debian Linux

Medium severity, CVSS 5.9. EPSS: 2% chance of exploitation in the next 30 days.

The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • Gnupg Gnupg: before 1.4.19 (fixed in 1.4.19)
  • Gnupg Libgcrypt: before 1.6.3 (fixed in 1.6.3)

Published 2019-11-29. Last modified 2026-06-17.