PT-2017-3948 · Openssl+7 · Openssl+7
Published
2017-11-02
·
Updated
2026-04-30
·
CVE-2017-3736
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenSSL versions prior to 1.0.2m
OpenSSL versions prior to 1.1.0g
Description
The issue is related to a carry propagating bug in the x86 64 Montgomery squaring procedure. This bug may allow a remote attacker to gain unauthorized access to information. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. However, attacks against DH are considered just feasible because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers.
Recommendations
For OpenSSL versions prior to 1.0.2m, update to version 1.0.2m or later.
For OpenSSL versions prior to 1.1.0g, update to version 1.1.0g or later.
As a temporary workaround, consider restricting access to systems using persistent DH parameters and a private key that is shared between multiple clients, until a patch is applied.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Freebsd
Openssl
Red Hat
Suse
Ubuntu
Virtualbox