PT-2016-7332 · Wolfssl · Wolfssl
Gorka Irazoqui Apecechea
+1
·
Published
2016-12-13
·
Updated
2016-12-24
·
CVE-2016-7439
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
wolfSSL versions prior to 3.9.10
Description
The issue in the C software implementation of RSA in wolfSSL makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.
Recommendations
For versions prior to 3.9.10, update to version 3.9.10 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wolfssl