wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wolfssl | Wolfssl | * | 3.6.8 (excluding) |
Mariadb-10.0 | Ubuntu | vivid | * |
Mariadb-5.5 | Ubuntu | trusty | * |
Mysql-5.5 | Ubuntu | precise | * |
Mysql-5.5 | Ubuntu | trusty | * |
Mysql-5.6 | Ubuntu | trusty | * |
Mysql-5.6 | Ubuntu | vivid | * |
Mysql-5.6 | Ubuntu | wily | * |
Percona-server-5.6 | Ubuntu | artful | * |
Percona-server-5.6 | Ubuntu | esm-apps/xenial | * |
Percona-server-5.6 | Ubuntu | vivid | * |
Percona-server-5.6 | Ubuntu | wily | * |
Percona-server-5.6 | Ubuntu | xenial | * |
Percona-server-5.6 | Ubuntu | yakkety | * |
Percona-server-5.6 | Ubuntu | zesty | * |
Percona-xtradb-cluster-5.5 | Ubuntu | trusty | * |
Percona-xtradb-cluster-5.6 | Ubuntu | vivid | * |
Percona-xtradb-cluster-5.6 | Ubuntu | wily | * |
Percona-xtradb-cluster-5.6 | Ubuntu | xenial | * |
Percona-xtradb-cluster-5.6 | Ubuntu | yakkety | * |