CVE Vulnerabilities

CVE-2013-5915

Published: Oct 04, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The RSA-CRT implementation in PolarSSL before 1.2.9 does not properly perform Montgomery multiplication, which might allow remote attackers to conduct a timing side-channel attack and retrieve RSA private keys.

Affected Software

NameVendorStart VersionEnd Version
PolarsslPolarssl*1.2.8 (including)
PolarsslPolarssl0.10.0 (including)0.10.0 (including)
PolarsslPolarssl0.10.1 (including)0.10.1 (including)
PolarsslPolarssl0.11.0 (including)0.11.0 (including)
PolarsslPolarssl0.11.1 (including)0.11.1 (including)
PolarsslPolarssl0.12.0 (including)0.12.0 (including)
PolarsslPolarssl0.12.1 (including)0.12.1 (including)
PolarsslPolarssl0.13.1 (including)0.13.1 (including)
PolarsslPolarssl0.14.0 (including)0.14.0 (including)
PolarsslPolarssl0.14.2 (including)0.14.2 (including)
PolarsslPolarssl0.14.3 (including)0.14.3 (including)
PolarsslPolarssl0.99-pre1 (including)0.99-pre1 (including)
PolarsslPolarssl0.99-pre3 (including)0.99-pre3 (including)
PolarsslPolarssl0.99-pre4 (including)0.99-pre4 (including)
PolarsslPolarssl0.99-pre5 (including)0.99-pre5 (including)
PolarsslPolarssl1.0.0 (including)1.0.0 (including)
PolarsslPolarssl1.1.0 (including)1.1.0 (including)
PolarsslPolarssl1.1.0-rc0 (including)1.1.0-rc0 (including)
PolarsslPolarssl1.1.0-rc1 (including)1.1.0-rc1 (including)
PolarsslPolarssl1.1.1 (including)1.1.1 (including)
PolarsslPolarssl1.1.2 (including)1.1.2 (including)
PolarsslPolarssl1.1.3 (including)1.1.3 (including)
PolarsslPolarssl1.1.4 (including)1.1.4 (including)
PolarsslPolarssl1.1.5 (including)1.1.5 (including)
PolarsslPolarssl1.1.6 (including)1.1.6 (including)
PolarsslPolarssl1.1.8 (including)1.1.8 (including)
PolarsslPolarssl1.2.0 (including)1.2.0 (including)
PolarsslPolarssl1.2.1 (including)1.2.1 (including)
PolarsslPolarssl1.2.2 (including)1.2.2 (including)
PolarsslPolarssl1.2.3 (including)1.2.3 (including)
PolarsslPolarssl1.2.4 (including)1.2.4 (including)
PolarsslPolarssl1.2.5 (including)1.2.5 (including)
PolarsslPolarssl1.2.6 (including)1.2.6 (including)
PolarsslPolarssl1.2.7 (including)1.2.7 (including)
MbedtlsUbuntuupstream*
PolarsslUbuntulucid*
PolarsslUbuntuprecise*
PolarsslUbuntuquantal*
PolarsslUbunturaring*
PolarsslUbuntusaucy*
PolarsslUbuntuupstream*

References