Wind River Support Network

HomeDefectsLIN8-2207
Fixed

LIN8-2207 : Security Advisory - openssl - CVE-2015-3193

Created: Dec 14, 2015    Updated: Dec 3, 2018
Resolved Date: Jan 6, 2016
Previous ID: LIN7-5305
Found In Version: 8.0
Fix Version: 8.0.0.1
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 platform, as used by the BN_mod_exp function, mishandles carry propagation and produces incorrect output, which makes it easier for remote attackers to obtain sensitive private-key information via an attack against use of a (1) Diffie-Hellman (DH) or (2) Diffie-Hellman Ephemeral (DHE) ciphersuite.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-3193

Other Downloads


CVEs


Live chat
Online