debian · CVE-2018-6829

Quick triage

Priority: unimportant 公開: Updated: Thu, 23 Jul 2026 01:18:52 GMT

参照: Official debian advisory, NVD, CVE.org · CVE 詳細

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-6829 unimportant priority: Debian including 2 source packages (gnupg1, libgcrypt20), 10 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 10.

Description:

cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation.

cvelogic Threat Intelligence