PT-2021-6992 · Openssl+1 · Openssl+1
Bernd Edlinger
·
Published
2021-12-10
·
Updated
2026-04-27
·
CVE-2021-4160
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenSSL versions 1.0.2 through 1.0.2zb
OpenSSL versions 1.1.1 through 1.1.1l
OpenSSL version 3.0.0
Description
The issue is related to a carry propagation bug in the MIPS32 and MIPS64 squaring procedure of the OpenSSL library, which can lead to the compromise of elliptic curve algorithms, including some of the TLS 1.3 default curves. This bug may allow a remote attacker to disclose protected information, particularly if private keys are reused. However, the prerequisites for an attack are considered unlikely, and the impact was not analyzed in detail. The amount of resources required for such an attack would be significant.
Recommendations
For OpenSSL versions 1.0.2 through 1.0.2zb, update to version 1.0.2zc or apply the fix from git commit 6fc1aaaf3.
For OpenSSL versions 1.1.1 through 1.1.1l, update to version 1.1.1m.
For OpenSSL version 3.0.0, update to version 3.0.1.
Exploit
Fix
Use of a Broken Cryptographic Algorithm
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Openssl