Vulnerability CVE-2015-7744: Information
Description
wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.
Severity: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
mariadb | sisyphus | 10.1.9-alt1 | 10.11.8-alt1 | ALT-PU-2015-2037-1 | 153988 | Fixed |
mariadb | p10 | 10.1.9-alt1 | 10.6.18-alt1 | ALT-PU-2015-2037-1 | 153988 | Fixed |
mariadb | p9 | 10.1.9-alt1 | 10.4.34-alt0.M90P.1 | ALT-PU-2015-2037-1 | 153988 | Fixed |
mariadb | c10f1 | 10.1.9-alt1 | 10.6.18-alt1 | ALT-PU-2015-2037-1 | 153988 | Fixed |
mariadb | c9f2 | 10.1.9-alt1 | 10.6.18-alt1 | ALT-PU-2015-2037-1 | 153988 | Fixed |
mariadb | c7 | 10.3.14-alt0.M70C.1 | 10.3.14-alt0.M70C.1 | ALT-PU-2019-1992-1 | 231405 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://people.redhat.com/~fweimer/rsa-crt-leaks.pdf |
|
https://wolfssl.com/wolfSSL/Blog/Entries/2015/9/17_Two_Vulnerabilities_Recently_Found%2C_An_Attack_on_RSA_using_CRT_and_DoS_Vulnerability_With_DTLS.html |
|
http://wolfssl.com/wolfSSL/Docs-wolfssl-changelog.html |
|
http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html |
|
https://securityblog.redhat.com/2015/09/02/factoring-rsa-keys-with-tls-perfect-forward-secrecy/ |
|
openSUSE-SU-2016:0367 |
|
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html |
|
openSUSE-SU-2016:0377 |
|
1034708 |
|