PT-2016-1367 · Openssl+3 · Openssl+3

Published

2016-01-28

·

Updated

2024-06-15

·

CVE-2016-0701

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.0.2 through 1.0.2e
Description The issue is related to the DH check pub key function in the crypto/dh/dh check.c file, which does not ensure that prime numbers are appropriate for Diffie-Hellman (DH) key exchange. This makes it easier for remote attackers to discover a private DH exponent by making multiple handshakes with a peer that chose an inappropriate number. The vulnerability can be exploited to allow an unauthenticated, remote attacker to conduct man-in-the-middle attacks on an SSL/TLS connection.
Recommendations For OpenSSL versions 1.0.2 through 1.0.2e, update to version 1.0.2f or later to resolve the issue. At the moment, there is no information about additional mitigation measures for this vulnerability.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1058
ALT-PU-2016-1184
BDU:2016-00666
CVE-2016-0701
MGASA-2016-0056
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1

Affected Products

Alt Linux
Cisco Nexus
Openssl
Suse