CVE Vulnerabilities

CVE-2015-7744

Published: Jan 22, 2016 | Modified: Aug 29, 2022
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM

wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.

Affected Software

Name Vendor Start Version End Version
Wolfssl Wolfssl * 3.6.8 (excluding)
Mariadb-10.0 Ubuntu vivid *
Mariadb-5.5 Ubuntu trusty *
Mysql-5.5 Ubuntu precise *
Mysql-5.5 Ubuntu trusty *
Mysql-5.6 Ubuntu trusty *
Mysql-5.6 Ubuntu vivid *
Mysql-5.6 Ubuntu wily *
Percona-server-5.6 Ubuntu artful *
Percona-server-5.6 Ubuntu esm-apps/xenial *
Percona-server-5.6 Ubuntu vivid *
Percona-server-5.6 Ubuntu wily *
Percona-server-5.6 Ubuntu xenial *
Percona-server-5.6 Ubuntu yakkety *
Percona-server-5.6 Ubuntu zesty *
Percona-xtradb-cluster-5.5 Ubuntu trusty *
Percona-xtradb-cluster-5.6 Ubuntu vivid *
Percona-xtradb-cluster-5.6 Ubuntu wily *
Percona-xtradb-cluster-5.6 Ubuntu xenial *
Percona-xtradb-cluster-5.6 Ubuntu yakkety *

References