PT-2017-3948 · Openssl+7 · Openssl+7

Publicado

2017-11-02

·

Atualizado

2026-04-30

·

CVE-2017-3736

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 1.0.2m OpenSSL versions prior to 1.1.0g
Description The issue is related to a carry propagating bug in the x86 64 Montgomery squaring procedure. This bug may allow a remote attacker to gain unauthorized access to information. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. However, attacks against DH are considered just feasible because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers.
Recommendations For OpenSSL versions prior to 1.0.2m, update to version 1.0.2m or later. For OpenSSL versions prior to 1.1.0g, update to version 1.1.0g or later. As a temporary workaround, consider restricting access to systems using persistent DH parameters and a private key that is shared between multiple clients, until a patch is applied.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2586
BDU:2020-02913
CESA-2018_0998
CVE-2017-3736
DSA-4017-1
DSA-4018-1
MGASA-2017-0405
MGASA-2018-0101
OPENSUSE-SU-2024:11126-1
OPENSUSE-SU-2024:11127-1
RHSA-2018:0998
RHSA-2018:2185
RHSA-2018:2186
RHSA-2018:2568
RHSA-2018:2575
RHSA-2018:2713
RHSA-2018_0998
RHSA-2018_2568
RHSA-2018_2575
SUSE-FU-2022:0445-1
SUSE-SU-2017:3169-1
SUSE-SU-2018:0002-1
SUSE-SU-2018:0293-1
SUSE-SU-2018:2839-1
SUSE-SU-2018:2839-2
SUSE-SU-2018:3082-1
SUSE-SU-2019:14246-1
SUSE-SU-2019_14246-1
USN-3475-1

Produtos afetados

Alt Linux
Centos
Freebsd
Openssl
Red Hat
Suse
Ubuntu
Virtualbox