Описание
wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | mysql55-mysql | Not affected | ||
Red Hat Enterprise Linux 6 | mysql | Not affected | ||
Red Hat Enterprise Linux 7 | mariadb | Not affected | ||
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse) | mariadb-galera | Not affected | ||
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | mariadb-galera | Not affected | ||
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | mariadb-galera | Not affected | ||
Red Hat Software Collections | mariadb55-mariadb | Not affected | ||
Red Hat Software Collections | mysql55-mysql | Not affected | ||
Red Hat Software Collections | rh-mariadb100-mariadb | Not affected | ||
Red Hat Software Collections | rh-mysql56-mysql | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
2.6 Low
CVSS2
Связанные уязвимости
wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.
wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.
wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults ...
wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.
Уязвимость системы управления базами данных MySQL, позволяющая нарушителю получить доступ на чтение данных
EPSS
2.6 Low
CVSS2