CVE-2011-4354
published 2012-01-27CVE-2011-4354: crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE…
PriorityP431medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
4.04%
89.5th percentile
crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE cipher suites, uses an incorrect modular reduction algorithm in its implementation of the P-256 and P-384 NIST elliptic curves, which allows remote attackers to obtain the private key of a TLS server via multiple handshake attempts.
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 0.9.8o-4squeeze3 (bookworm) | openssl 0.9.8o-4squeeze3 (bookworm) |
| openssl | openssl | <= 0.9.8g | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
vendor_ubuntu2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wph7-m6hx-9r8m: crypto/bn/bn_nist
ghsa_unreviewed·2022-05-17
CVE-2011-4354 [MEDIUM] GHSA-wph7-m6hx-9r8m: crypto/bn/bn_nist
crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE cipher suites, uses an incorrect modular reduction algorithm in its implementation of the P-256 and P-384 NIST elliptic curves, which allows remote attackers to obtain the private key of a TLS server via multiple handshake attempts.
OSV
CVE-2011-4354: crypto/bn/bn_nist
osv·2012-01-27·CVSS 5.8
CVE-2011-4354 [MEDIUM] CVE-2011-4354: crypto/bn/bn_nist
crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE cipher suites, uses an incorrect modular reduction algorithm in its implementation of the P-256 and P-384 NIST elliptic curves, which allows remote attackers to obtain the private key of a TLS server via multiple handshake attempts.
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2012-02-09·CVSS 2.6
CVE-2012-0027 [LOW] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Multiple vulnerabilities exist in OpenSSL that could expose
sensitive information or cause applications to crash.
It was discovered that the elliptic curve cryptography (ECC) subsystem
in OpenSSL, when using the Elliptic Curve Digital Signature Algorithm
(ECDSA) for the ECDHE_ECDSA cipher suite, did not properly implement
curves over binary fields. This could allow an attacker to determine
private keys via a timing attack. This issue only affected Ubuntu 8.04
LTS, Ubuntu 10.04 LTS, Ubuntu 10.10 and Ubuntu 11.04. (CVE-2011-1945)
Adam Langley discovered that the ephemeral Elliptic Curve
Diffie-Hellman (ECDH) functionality in OpenSSL did not ensure thread
safety while processing handshake messages from clients. This
could allow a remote attacker to c
Red Hat
openssl: ECC private leak (disclosure of TLS server's private key)
vendor_redhat·2011-11-24·CVSS 5.8
CVE-2011-4354 [MEDIUM] openssl: ECC private leak (disclosure of TLS server's private key)
openssl: ECC private leak (disclosure of TLS server's private key)
crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE cipher suites, uses an incorrect modular reduction algorithm in its implementation of the P-256 and P-384 NIST elliptic curves, which allows remote attackers to obtain the private key of a TLS server via multiple handshake attempts.
Statement: This issue did not affect the versions of openssl as shipped with Red Hat Enterprise Linux 3, 4, 5, or 6 as they did not include support for the ECDH or ECDHE ciphers.
Package: openssl (Red Hat Enterprise Linux 4) - Not affected
Package: openssl096b (Red Hat Enterprise Linux 4) - Not affected
Package: openssl (Red Hat Enterprise
Debian
CVE-2011-4354: openssl - crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stu...
vendor_debian·2011·CVSS 5.8
CVE-2011-4354 [MEDIUM] CVE-2011-4354: openssl - crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stu...
crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE cipher suites, uses an incorrect modular reduction algorithm in its implementation of the P-256 and P-384 NIST elliptic curves, which allows remote attackers to obtain the private key of a TLS server via multiple handshake attempts.
Scope: local
bookworm: resolved (fixed in 0.9.8o-4squeeze3)
bullseye: resolved (fixed in 0.9.8o-4squeeze3)
forky: resolved (fixed in 0.9.8o-4squeeze3)
sid: resolved (fixed in 0.9.8o-4squeeze3)
trixie: resolved (fixed in 0.9.8o-4squeeze3)
No detection rules found.
No public exploits indexed.
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
Bugzilla
CVE-2011-4354 openssl: ECC private leak (disclosure of TLS server's private key)
bugzilla·2011-11-28·CVSS 5.8
CVE-2011-4354 [MEDIUM] CVE-2011-4354 openssl: ECC private leak (disclosure of TLS server's private key)
CVE-2011-4354 openssl: ECC private leak (disclosure of TLS server's private key)
It was reported that OpenSSL 0.9.8g (only in the 32-bit build) was vulnerable to a bug where, in extremely rare instances, the bug would cause incorrect computation of finite field operations when using NIST elliptic curves P-256 or P-384. This flaw could allow for the retrieval of a TLS server's private key. A paper was published [1] describing the attack.
There are some very specific pre-requisites for a successful attack:
- OpenSSL 0.9.8g (32-bit build)
- use of NIST elliptic curve P-256 and/or P-384
- the use of ECDH family ciphers and/or the use of ECDHE family ciphers *and* the lack of SSL_OP_SINGLE_ECDH_USE context option
This bug is corrected in OpenSSL >= 0.9.8h and does not affect earlier version
http://crypto.di.uminho.pt/CACE/CT-RSA2012-openssl-src.ziphttp://cvs.openssl.org/filediff?f=openssl/crypto/bn/bn_nist.c&v1=1.14&v2=1.21http://eprint.iacr.org/2011/633http://marc.info/?t=119271238800004http://openwall.com/lists/oss-security/2011/12/01/6http://rt.openssl.org/Ticket/Display.html?id=1593&user=guest&pass=guesthttp://www.debian.org/security/2012/dsa-2390https://bugzilla.redhat.com/show_bug.cgi?id=757909http://crypto.di.uminho.pt/CACE/CT-RSA2012-openssl-src.ziphttp://cvs.openssl.org/filediff?f=openssl/crypto/bn/bn_nist.c&v1=1.14&v2=1.21http://eprint.iacr.org/2011/633http://marc.info/?t=119271238800004http://openwall.com/lists/oss-security/2011/12/01/6http://rt.openssl.org/Ticket/Display.html?id=1593&user=guest&pass=guesthttp://www.debian.org/security/2012/dsa-2390https://bugzilla.redhat.com/show_bug.cgi?id=757909
2012-01-27
Published