PT-2017-4101 · Openssl+6 · Openssl+6

Publicado

2017-12-06

·

Atualizado

2024-06-15

·

CVE-2017-3738

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to the fixed version
Description The vulnerability in the AVX2 Montgomery procedure of the OpenSSL library is related to insufficient protection of service data. Exploitation of this issue may allow a remote attacker to gain unauthorized access to protected information using a closed key DH1024. The vulnerability is caused by an overflow in the multiplication procedure according to the Montgomery algorithm AVX2 when raising to a power modulo a 1024-bit module. Attacks on RSA and DSA are considered difficult to implement and unlikely. However, attacks on Diffie-Hellman algorithms (DH1024) are considered difficult but possible, as the main part of the work to extract data about the secret key can be performed without connecting to the system. Significant resources are required to carry out such attacks. To attack a TLS server, it is necessary to distribute the secret key DH1024 among a large number of clients. Only processors that support AVX2 extensions (not ADX) are vulnerable, such as Intel Haswell 4th generation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Overflow

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2778
ALT-PU-2018-1303
BDU:2021-03037
CESA-2018_0998
CVE-2017-3738
DSA-4065-1
DSA-4157-1
MGASA-2017-0453
OPENSUSE-SU-2017_3345-1
OPENSUSE-SU-2024:11126-1
OPENSUSE-SU-2024:11127-1
RHSA-2018:0998
RHSA-2018:2185
RHSA-2018:2186
RHSA-2018_0998
SUSE-FU-2022:0445-1
SUSE-SU-2017:3343-1
SUSE-SU-2018:0002-1
SUSE-SU-2018:0293-1
SUSE-SU-2019:14246-1
SUSE-SU-2019_14246-1
USN-3512-1

Produtos afetados

Alt Linux
Centos
Freebsd
Openssl
Red Hat
Suse
Ubuntu