CVE-2007-3108
openssl: RSA side-channel attack
Severity Score
1.2
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.
La funciĆ³n BN_from_montgomery en el crypto/bn/bn_mont.c del OpenSSL 0.9.8e y anteriores, no interpreta adecuadamente la multiplicaciĆ³n Montgomery, lo que permite a usuarios locales llevar a cabo ataques por canal colateral (side-channel) y recuperar claves privadas RSA.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-06-07 CVE Reserved
- 2007-08-08 CVE Published
- 2024-08-07 CVE Updated
- 2024-10-03 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (48)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/bid/25163 | 2018-10-16 |
URL | Date | SRC |
---|---|---|
http://security.gentoo.org/glsa/glsa-200710-06.xml | 2018-10-16 | |
http://www.debian.org/security/2008/dsa-1571 | 2018-10-16 | |
http://www.gentoo.org/security/en/glsa/glsa-200805-07.xml | 2018-10-16 | |
http://www.mandriva.com/security/advisories?name=MDKSA-2007:193 | 2018-10-16 | |
http://www.redhat.com/support/errata/RHSA-2007-0813.html | 2018-10-16 | |
http://www.redhat.com/support/errata/RHSA-2007-0964.html | 2018-10-16 | |
http://www.redhat.com/support/errata/RHSA-2007-1003.html | 2018-10-16 | |
https://usn.ubuntu.com/522-1 | 2018-10-16 | |
https://access.redhat.com/security/cve/CVE-2007-3108 | 2007-11-15 | |
https://bugzilla.redhat.com/show_bug.cgi?id=245732 | 2007-11-15 |