CVE-2019-13627
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.
Date published : 2019-09-25
https://security.gentoo.org/glsa/202003-32
https://github.com/gpg/libgcrypt/releases/tag/libgcrypt-1.8.5