{"id":"CVE-2014-5270","details":"Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576.","modified":"2026-04-16T06:23:49.130619831Z","published":"2014-10-10T01:55:10Z","references":[{"type":"ADVISORY","url":"http://lists.gnupg.org/pipermail/gnupg-announce/2014q3/000352.html"},{"type":"ADVISORY","url":"http://openwall.com/lists/oss-security/2014/08/16/2"},{"type":"ADVISORY","url":"http://www.debian.org/security/2014/dsa-3024"},{"type":"ADVISORY","url":"http://www.debian.org/security/2014/dsa-3073"},{"type":"ARTICLE","url":"http://openwall.com/lists/oss-security/2014/08/16/2"},{"type":"ARTICLE","url":"http://www.cs.tau.ac.il/~tromer/handsoff/"},{"type":"FIX","url":"http://lists.gnupg.org/pipermail/gnupg-announce/2014q3/000352.html"}],"schema_version":"1.7.5"}