CVE Vulnerabilities

CVE-2007-3108

Published: Aug 08, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
1.2 LOW
AV:L/AC:H/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE

The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.

Affected Software

Name Vendor Start Version End Version
Openssl Openssl * 0.9.8e (including)
Red Hat Enterprise Linux 2.1 RedHat openssl-0:0.9.6b-48 *
Red Hat Enterprise Linux 3 RedHat openssl-0:0.9.7a-33.24 *
Red Hat Enterprise Linux 4 RedHat openssl-0:0.9.7a-43.17.el4_6.1 *
Red Hat Enterprise Linux 5 RedHat openssl-0:0.9.8b-8.3.el5_0.2 *
Openssl Ubuntu dapper *
Openssl Ubuntu devel *
Openssl Ubuntu edgy *
Openssl Ubuntu feisty *
Openssl Ubuntu gutsy *
Openssl Ubuntu hardy *
Openssl Ubuntu intrepid *
Openssl Ubuntu jaunty *
Openssl Ubuntu karmic *
Openssl Ubuntu upstream *
Openssl097 Ubuntu dapper *
Openssl097 Ubuntu edgy *
Openssl097 Ubuntu feisty *

References