Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-1945

Опубликовано: 31 мая 2011
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 2.6

Описание

The elliptic curve cryptography (ECC) subsystem in OpenSSL 1.0.0d and earlier, when the Elliptic Curve Digital Signature Algorithm (ECDSA) is used for the ECDHE_ECDSA cipher suite, does not properly implement curves over binary fields, which makes it easier for context-dependent attackers to determine private keys via a timing attack and a lattice calculation.

РелизСтатусПримечание
devel

released

1.0.0e-2ubuntu1
hardy

released

0.9.8g-4ubuntu3.15
lucid

released

0.9.8k-7ubuntu8.8
maverick

released

0.9.8o-1ubuntu4.6
natty

released

0.9.8o-5ubuntu1.2
oneiric

released

1.0.0e-2ubuntu1
upstream

needed

Показывать по

EPSS

Процентиль: 89%
0.04848
Низкий

2.6 Low

CVSS2

Связанные уязвимости

redhat
больше 14 лет назад

The elliptic curve cryptography (ECC) subsystem in OpenSSL 1.0.0d and earlier, when the Elliptic Curve Digital Signature Algorithm (ECDSA) is used for the ECDHE_ECDSA cipher suite, does not properly implement curves over binary fields, which makes it easier for context-dependent attackers to determine private keys via a timing attack and a lattice calculation.

nvd
больше 14 лет назад

The elliptic curve cryptography (ECC) subsystem in OpenSSL 1.0.0d and earlier, when the Elliptic Curve Digital Signature Algorithm (ECDSA) is used for the ECDHE_ECDSA cipher suite, does not properly implement curves over binary fields, which makes it easier for context-dependent attackers to determine private keys via a timing attack and a lattice calculation.

debian
больше 14 лет назад

The elliptic curve cryptography (ECC) subsystem in OpenSSL 1.0.0d and ...

github
больше 3 лет назад

The elliptic curve cryptography (ECC) subsystem in OpenSSL 1.0.0d and earlier, when the Elliptic Curve Digital Signature Algorithm (ECDSA) is used for the ECDHE_ECDSA cipher suite, does not properly implement curves over binary fields, which makes it easier for context-dependent attackers to determine private keys via a timing attack and a lattice calculation.

CVSS3: 7.3
fstec
около 12 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 89%
0.04848
Низкий

2.6 Low

CVSS2