cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-02-07T23:00:00

Updated: 2020-01-15T19:15:22

Reserved: 2018-02-07T00:00:00


Link: CVE-2018-6829

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2018-02-07T23:29:01.703

Modified: 2020-01-15T20:15:18.557


Link: CVE-2018-6829

JSON object: View

cve-icon Redhat Information

No data.

CWE