CVE-2007-3108
published 2007-08-08CVE-2007-3108: The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow…
PriorityP47low1.2CVSS 2.0
AVLACHAuNCPINAN
EPSS
0.41%
33.1th percentile
The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 0.9.8e-6 (bookworm) | openssl 0.9.8e-6 (bookworm) |
| openssl | openssl | <= 0.9.8e | — |
| openssl | openssl | >= 0 < 0.9.8e-6 | 0.9.8e-6 |
| openssl | openssl | >= 0 < 0.9.8e-6 | 0.9.8e-6 |
| openssl | openssl | >= 0 < 0.9.8e-6 | 0.9.8e-6 |
| openssl | openssl | >= 0 < 0.9.8e-6 | 0.9.8e-6 |
CVSS provenance
nvdv2.01.2LOWAV:L/AC:H/Au:N/C:P/I:N/A:N
osv1.2LOW
vendor_debian1.2LOW
vendor_redhat1.2LOW
vendor_ubuntu1.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p7c7-98j2-8p2x: The BN_from_montgomery function in crypto/bn/bn_mont
ghsa_unreviewed·2022-05-01
CVE-2007-3108 [LOW] GHSA-p7c7-98j2-8p2x: The BN_from_montgomery function in crypto/bn/bn_mont
The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.
OSV
CVE-2007-3108: The BN_from_montgomery function in crypto/bn/bn_mont
osv·2007-08-08·CVSS 1.2
CVE-2007-3108 [LOW] CVE-2007-3108: The BN_from_montgomery function in crypto/bn/bn_mont
The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.
VMware
Updated service console patches.
vendor_vmware·2008-01-07·CVSS 1.2
CVE-2007-3108 [LOW] Updated service console patches.
VMSA-2008-0001: Updated service console patches.
Updated service console patches. VMware Security Advisory VMware Security Advisory Advisory ID: VMware Security Advisory Synopsis: Updated service console patches. VMware Security Advisory Issue date: VMware Security Advisory Updated on:
CVEs: CVE-2007-3108, CVE-2007-4572, CVE-2007-5116, CVE-2007-5135, CVE-2007-5191, CVE-2007-5360, CVE-2007-5398
Ubuntu
openssl vulnerabilities
vendor_ubuntu·2007-09-28·CVSS 1.2
CVE-2007-3108 [LOW] openssl vulnerabilities
Title: openssl vulnerabilities
Summary: openssl vulnerabilities
It was discovered that OpenSSL did not correctly perform Montgomery
multiplications. Local attackers might be able to reconstruct RSA
private keys by examining another user's OpenSSL processes. (CVE-2007-3108)
Moritz Jodeit discovered that OpenSSL's SSL_get_shared_ciphers function
did not correctly check the size of the buffer it was writing to.
A remote attacker could exploit this to write one NULL byte past the end of
an application's cipher list buffer, possibly leading to arbitrary code
execution or a denial of service. (CVE-2007-5135)
Instructions: After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Red Hat
openssl: RSA side-channel attack
vendor_redhat·2007-08-01·CVSS 1.2
CVE-2007-3108 [LOW] openssl: RSA side-channel attack
openssl: RSA side-channel attack
The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.
Debian
CVE-2007-3108: openssl - The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and ear...
vendor_debian·2007·CVSS 1.2
CVE-2007-3108 [LOW] CVE-2007-3108: openssl - The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and ear...
The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.
Scope: local
bookworm: resolved (fixed in 0.9.8e-6)
bullseye: resolved (fixed in 0.9.8e-6)
forky: resolved (fixed in 0.9.8e-6)
sid: resolved (fixed in 0.9.8e-6)
trixie: resolved (fixed in 0.9.8e-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-3108 openssl RSA weakness
bugzilla·2007-08-02·CVSS 1.2
CVE-2007-3108 [LOW] CVE-2007-3108 openssl RSA weakness
CVE-2007-3108 openssl RSA weakness
+++ This bug was initially created as a clone of Bug #245732 +++
The OpenSSL team made the following commit publically to the 0.9.8 head:
http://cvs.openssl.org/chngview?cn=16275
This is a possible weakness in OpenSSL which could allow a local user in certain
circumstances to divulge information about private keys being used. For
example if a server has a SSL web server on it, a local unprivileged user may be
able to get hold of the key.
I'm not sure in practice how possible this would be; it would rely on a system
that isn't doing much else that could interfere with some spy process designed
to figure out this information (and probably won't be possible if you have a
server handling a lot of traffic, has more than one key, lots of local
processes, an
Bugzilla
CVE-2007-3108 openssl various flaws [FC6]
bugzilla·2007-08-02·CVSS 1.2
CVE-2007-3108 [LOW] CVE-2007-3108 openssl various flaws [FC6]
CVE-2007-3108 openssl various flaws [FC6]
FC6 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
Fedora apologizes that these issues have not been resolved yet. We're
sorry it's taken so long for your bug to be properly triaged and acted
on. We appreciate the time you took to report this issue and want to
make sure no important bugs slip through the cracks.
If you're currently running a version of Fedora Core between 1 and 6,
please note that Fedora no longer maintains these releases. We strongly
encourage you to upgrade to a current Fedora release. In order to
refocus our efforts as a project we are flagging all of the open bugs
for releases which are no longer maintained and closing them.
http:/
Bugzilla
CVE-2007-3108 openssl various flaws [F7]
bugzilla·2007-08-02·CVSS 1.2
CVE-2007-3108 [LOW] CVE-2007-3108 openssl various flaws [F7]
CVE-2007-3108 openssl various flaws [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
openssl-0.9.8b-14.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-3108 openssl various flaws [Fdevel]
bugzilla·2007-08-02·CVSS 1.2
CVE-2007-3108 [LOW] CVE-2007-3108 openssl various flaws [Fdevel]
CVE-2007-3108 openssl various flaws [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Bugzilla
Placeholder for VU#724968 investigation
bugzilla·2007-07-03·CVSS 1.2
[LOW] Placeholder for VU#724968 investigation
Placeholder for VU#724968 investigation
Cert forwarded information about VU#724968 which is a flaw in a different crypto product but which they worry may also affect NSS. This is a placeholder while we investigate (nelsonb and rrelyea have the paper) in case we need to start tracking getting a fix into releases.
Discussion:
Cert sent an update, OpenSSL has fixed this in their implementation. Any information on whether we had the same issue in NSS?
- - - - - -
Hello,
The OpenSSL team has released a patch for VU#724968 (CVE-2007-3108), and has made it publicly available here:
http://cvs.openssl.org/chngview?cn=16275
We have published vulnerability note VU#724968 (http://www.kb.cert.org/vuls/id/724968). If you send us a vendor statement, we will add it to the
note.
---
OpenSSL patch w
Bugzilla
CVE-2007-3108 openssl: RSA side-channel attack
bugzilla·2007-06-26·CVSS 1.2
CVE-2007-3108 [LOW] CVE-2007-3108 openssl: RSA side-channel attack
CVE-2007-3108 openssl: RSA side-channel attack
The OpenSSL team made the following commit publically to the 0.9.8 head:
http://cvs.openssl.org/chngview?cn=16275
This is a possible weakness in OpenSSL which could allow a local user in certain
circumstances to divulge information about private keys being used. For
example if a server has a SSL web server on it, a local unprivileged user may be
able to get hold of the key.
I'm not sure in practice how possible this would be; it would rely on a system
that isn't doing much else that could interfere with some spy process designed
to figure out this information (and probably won't be possible if you have a
server handling a lot of traffic, has more than one key, lots of local
processes, and so on).
It's similar to previous issues and is rate
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
http://cvs.openssl.org/chngview?cn=16275http://lists.vmware.com/pipermail/security-announce/2008/000002.htmlhttp://openssl.org/news/patch-CVE-2007-3108.txthttp://secunia.com/advisories/26411http://secunia.com/advisories/26893http://secunia.com/advisories/27021http://secunia.com/advisories/27078http://secunia.com/advisories/27097http://secunia.com/advisories/27205http://secunia.com/advisories/27330http://secunia.com/advisories/27770http://secunia.com/advisories/27870http://secunia.com/advisories/28368http://secunia.com/advisories/30161http://secunia.com/advisories/30220http://secunia.com/advisories/31467http://secunia.com/advisories/31489http://secunia.com/advisories/31531http://security.gentoo.org/glsa/glsa-200710-06.xmlhttp://support.attachmate.com/techdocs/2374.htmlhttp://support.avaya.com/elmodocs2/security/ASA-2007-485.htmhttp://www.bluecoat.com/support/securityadvisories/advisory_openssl_rsa_key_reconstruction_vulnerabilityhttp://www.debian.org/security/2008/dsa-1571http://www.gentoo.org/security/en/glsa/glsa-200805-07.xmlhttp://www.kb.cert.org/vuls/id/724968http://www.kb.cert.org/vuls/id/RGII-74KLP3http://www.mandriva.com/security/advisories?name=MDKSA-2007:193http://www.redhat.com/support/errata/RHSA-2007-0813.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0964.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1003.htmlhttp://www.securityfocus.com/archive/1/476341/100/0/threadedhttp://www.securityfocus.com/archive/1/485936/100/0/threadedhttp://www.securityfocus.com/archive/1/486859/100/0/threadedhttp://www.securityfocus.com/bid/25163http://www.vmware.com/security/advisories/VMSA-2008-0001.htmlhttp://www.vmware.com/security/advisories/VMSA-2008-0013.htmlhttp://www.vupen.com/english/advisories/2007/2759http://www.vupen.com/english/advisories/2007/4010http://www.vupen.com/english/advisories/2008/0064http://www.vupen.com/english/advisories/2008/2361http://www.vupen.com/english/advisories/2008/2362http://www.vupen.com/english/advisories/2008/2396https://issues.rpath.com/browse/RPL-1613https://issues.rpath.com/browse/RPL-1633https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9984https://usn.ubuntu.com/522-1/http://cvs.openssl.org/chngview?cn=16275http://lists.vmware.com/pipermail/security-announce/2008/000002.htmlhttp://openssl.org/news/patch-CVE-2007-3108.txthttp://secunia.com/advisories/26411http://secunia.com/advisories/26893http://secunia.com/advisories/27021http://secunia.com/advisories/27078http://secunia.com/advisories/27097http://secunia.com/advisories/27205http://secunia.com/advisories/27330http://secunia.com/advisories/27770http://secunia.com/advisories/27870http://secunia.com/advisories/28368http://secunia.com/advisories/30161http://secunia.com/advisories/30220http://secunia.com/advisories/31467http://secunia.com/advisories/31489http://secunia.com/advisories/31531http://security.gentoo.org/glsa/glsa-200710-06.xmlhttp://support.attachmate.com/techdocs/2374.htmlhttp://support.avaya.com/elmodocs2/security/ASA-2007-485.htmhttp://www.bluecoat.com/support/securityadvisories/advisory_openssl_rsa_key_reconstruction_vulnerabilityhttp://www.debian.org/security/2008/dsa-1571http://www.gentoo.org/security/en/glsa/glsa-200805-07.xmlhttp://www.kb.cert.org/vuls/id/724968http://www.kb.cert.org/vuls/id/RGII-74KLP3http://www.mandriva.com/security/advisories?name=MDKSA-2007:193http://www.redhat.com/support/errata/RHSA-2007-0813.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0964.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1003.htmlhttp://www.securityfocus.com/archive/1/476341/100/0/threadedhttp://www.securityfocus.com/archive/1/485936/100/0/threadedhttp://www.securityfocus.com/archive/1/486859/100/0/threadedhttp://www.securityfocus.com/bid/25163http://www.vmware.com/security/advisories/VMSA-2008-0001.htmlhttp://www.vmware.com/security/advisories/VMSA-2008-0013.htmlhttp://www.vupen.com/english/advisories/2007/2759http://www.vupen.com/english/advisories/2007/4010http://www.vupen.com/english/advisories/2008/0064http://www.vupen.com/english/advisories/2008/2361http://www.vupen.com/english/advisories/2008/2362http://www.vupen.com/english/advisories/2008/2396https://issues.rpath.com/browse/RPL-1613https://issues.rpath.com/browse/RPL-1633https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9984https://usn.ubuntu.com/522-1/
2007-08-08
Published