[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

OpenSSL - (bulletinapr2018)

ID: oval:org.secpod.oval:def:2101940Date: (C)2019-10-11   (M)2024-04-17
Class: PATCHFamily: unix




There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH1024 are considered just feasible, because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be significant. However, for an attack on TLS to be meaningful, the server would have to share the DH1024 private key among multiple clients, which is no longer an option since CVE-2016-0701. This only affects processors that support the AVX2 but not ADX extensions like Intel Haswell (4th generation). Note: The impact from this issue is similar to CVE-2017-3736, CVE-2017-3732 and CVE-2015-3193. OpenSSL version 1.0.2-1.0.2m and 1.1.0-1.1.0g are affected. Fixed in OpenSSL 1.0.2n. Due to the low severity of this issue we are not issuing a new release of OpenSSL 1.1.0 at this time. The fix will be included in OpenSSL 1.1.0h when it becomes available. The fix is also available in commit e502cc86d in the OpenSSL git repository.

Platform:
Sun Solaris 11
Product:
web/server/apache-24
web/server/apache-24/module/apache-ssl
web/server/apache-24/module/apache-ssl-fips-140
web/server/apache-24/module/apache-lua
web/server/apache-24/module/apache-ldap
web/server/apache-24/module/apache-gss
web/server/apache-24/module/apache-dbd
web/java-servlet/tomcat-8
web/java-servlet/tomcat-8/tomcat-examples
web/java-servlet/tomcat-8/tomcat-admin
web/curl
terminal/cssh
terminal/cssh-526
terminal/cssh-522
system/display-manager/gdm
system/display-manager/desktop-startup
runtime/tcl-8/tcl-sqlite-3
mail/thunderbird
mail/thunderbird/plugin/thunderbird-lightning
mail/mailman
library/speech/espeak
library/security/openssl
library/security/openssl/openssl-fips-140
library/python/pyatspi2
library/python/pyatspi2-35
library/python/pyatspi2-34
library/python/pyatspi2-27
library/perl-5/xml-simple
library/perl-5/xml-simple-526
library/perl-5/xml-simple-522
library/perl-5/xml-sax
library/perl-5/xml-sax-base
library/perl-5/xml-sax-base-526
library/perl-5/xml-sax-base-522
library/perl-5/xml-sax-526
library/perl-5/xml-sax-522
library/perl-5/xml-parser
library/perl-5/xml-parser-526
library/perl-5/xml-parser-522
library/perl-5/xml-namespacesupport
library/perl-5/xml-namespacesupport-526
library/perl-5/xml-namespacesupport-522
library/perl-5/xml-libxml
library/perl-5/xml-libxml-526
library/perl-5/xml-libxml-522
library/perl-5/pmtools
library/perl-5/pmtools-526
library/perl-5/pmtools-522
library/perl-5/perl-x11-protocol
library/perl-5/perl-x11-protocol-526
library/perl-5/perl-x11-protocol-522
library/perl-5/perl-tk
library/perl-5/perl-tk-526
library/perl-5/perl-tk-522
library/perl-5/net-ssleay
library/perl-5/net-ssleay-526
library/perl-5/net-ssleay-522
library/perl-5/gettext
library/perl-5/gettext-526
library/perl-5/gettext-522
library/perl-5/dbd-sqlite
library/perl-5/dbd-sqlite-526
library/perl-5/dbd-sqlite-522
library/perl-5/dbd-mysql
library/perl-5/dbd-mysql-526
library/perl-5/dbd-mysql-522
library/perl-5/database
library/perl-5/database-526
library/perl-5/database-522
library/perl-5/authen-pam
library/perl-5/authen-pam-526
library/perl-5/authen-pam-522
library/perl-5/CGI
library/perl-5/CGI-526
library/perl-5/CGI-522
library/liblouis
library/desktop/webkitgtk4
library/desktop/speech-dispatcher
library/desktop/dotconf
image/library/libjpeg
diagnostic/wireshark
diagnostic/wireshark/wireshark-common
diagnostic/wireshark/tshark
database/sqlite-3
database/sqlite-3/documentation
database/mysql-57
database/mysql-57/tests
database/mysql-57/library
database/mysql-57/embedded
database/mysql-57/client
database/mysql-56
database/mysql-56/tests
database/mysql-56/library
database/mysql-56/client
database/mysql-55
database/mysql-55/tests
database/mysql-55/library
database/mysql-55/client
Reference:
bulletinapr2018
CVE-2017-3738
CVE    1
CVE-2017-3738
CPE    1
cpe:/o:oracle:solaris:11

© SecPod Technologies