PT-2013-1216 · Openssl · Polarssl
Cyril Arnaud
+1
·
Publicado
2013-10-04
·
Atualizado
2013-11-30
·
CVE-2013-5915
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
PolarSSL versions prior to 1.3.0
PolarSSL versions prior to 1.2.9
Description
The issue concerns multiple vulnerabilities in the PolarSSL package, which can lead to disruption of protected information availability. These vulnerabilities can be exploited remotely. Specifically, the RSA-CRT implementation in PolarSSL does not properly perform Montgomery multiplication, potentially allowing remote attackers to conduct a timing side-channel attack and retrieve RSA private keys.
Recommendations
For PolarSSL versions prior to 1.3.0, update to version 1.3.0 or later to resolve the issue.
For PolarSSL versions prior to 1.2.9, update to version 1.2.9 or later to address the RSA-CRT implementation vulnerability.
As a temporary workaround, consider restricting access to sensitive information handled by PolarSSL until a patch is applied.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Polarssl