> We thank Werner Koch, lead developer of GnuPG, for the prompt response to our disclosure and the productive collaboration in adding suitable countermeasures.
"[...] If you are using a GnuPG version with a Libgcrypt version < 1.6.0, it is possible to mount the described side-channel attack on Elgamal encryption subkeys. [...]"
"We have disclosed our attack to GnuPG developers under CVE-2014-3591, suggested suitable countermeasures, and worked with the developers to test them. GnuPG 1.4.19 and Libgcrypt 1.6.3 (which underlies GnuPG 2.x), containing these countermeasures and resistant to the key-extraction attack described here, were released concurrently with the first public posting of these results."
Basically that Libcrypt 1.6.3 underlies GnuPG 2.x. But when I check my system:
You sound like if you're going to build the binary manually (using an axe or something). Just compile the latest version for your system. Your distribution's package manager should be up-to-date by now.
"[...] If you are using a GnuPG version with a Libgcrypt version < 1.6.0, it is possible to mount the described side-channel attack on Elgamal encryption subkeys. [...]"
https://lists.gnupg.org/pipermail/gnupg-announce/2014q3/0003...