Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-12437

Опубликовано: 15 июн. 2018
Источник: debian

Описание

LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libtomcryptfixed1.18.2-1package
libtomcryptno-dsastretchpackage
libtomcryptno-dsajessiepackage

Примечания

  • https://github.com/libtom/libtomcrypt/issues/407

  • https://github.com/libtom/libtomcrypt/pull/408

Связанные уязвимости

CVSS3: 4.9
ubuntu
больше 7 лет назад

LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

CVSS3: 5.5
redhat
больше 7 лет назад

LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

CVSS3: 4.9
nvd
больше 7 лет назад

LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.