Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-12437

Опубликовано: 13 июн. 2018
Источник: redhat
CVSS3: 5.5

Описание

LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

Отчет

This flaw was found to be a duplicate of CVE-2018-0495. Please see https://access.redhat.com/security/cve/CVE-2018-0495 for information about affected products and security errata.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5libtomcryptNot affected
Red Hat Ansible Engine 2libtomcryptNot affected
Red Hat Enterprise Linux 7libtomcryptNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-385
https://bugzilla.redhat.com/show_bug.cgi?id=1591904libtomcrypt: memory-cache side-channel attack on ECDSA signatures

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
ubuntu
больше 7 лет назад

LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

CVSS3: 4.9
nvd
больше 7 лет назад

LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

CVSS3: 4.9
debian
больше 7 лет назад

LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack o ...

5.5 Medium

CVSS3