CVE-2012-2130
published 2019-12-06CVE-2012-2130: A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RSA keys.
PriorityP343high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
2.20%
80.5th percentile
A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RSA keys.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | >= 0 < 1.3.4-1 | 1.3.4-1 |
| polarssl | polarssl | 1.0.0 – 1.1.1 | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-75jp-83j7-2672: A Security Bypass vulnerability exists in PolarSSL 0
ghsa_unreviewed·2022-04-23
CVE-2012-2130 [HIGH] CWE-326 GHSA-75jp-83j7-2672: A Security Bypass vulnerability exists in PolarSSL 0
A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RSA keys.
OSV
CVE-2012-2130: A Security Bypass vulnerability exists in PolarSSL 0
osv·2019-12-06·CVSS 7.4
CVE-2012-2130 [HIGH] CVE-2012-2130: A Security Bypass vulnerability exists in PolarSSL 0
A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RSA keys.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2130 polarssl: weak key generation in 0.99pre4 throught to 1.1.1 [fedora-17]
bugzilla·2012-05-17·CVSS 7.4
CVE-2012-2130 [HIGH] CVE-2012-2130 polarssl: weak key generation in 0.99pre4 throught to 1.1.1 [fedora-17]
CVE-2012-2130 polarssl: weak key generation in 0.99pre4 throught to 1.1.1 [fedora-17]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type
Bugzilla
CVE-2012-2130 polarssl: weak key generation in 0.99pre4 throught to 1.1.1
bugzilla·2012-05-17·CVSS 7.4
CVE-2012-2130 [HIGH] CVE-2012-2130 polarssl: weak key generation in 0.99pre4 throught to 1.1.1
CVE-2012-2130 polarssl: weak key generation in 0.99pre4 throught to 1.1.1
From the upstream advisory [1]:
During code migration a bug was introduced in PolarSSL 0.99-pre4. As a result the generation of Diffie Hellman value X is weak on the client and server. Only a part of the value X is filled with random data, instead of the whole value. (Determined by the server Diffie Hellman parameters). In addition, MPI primes are only generated within a limited subspace of the full prime space. Again only a part of the prime is filled with random data, instead of the whole value.
Impact
When a weak X is generated the resulting Diffie Hellman key exchange is weaker. This makes it easier for an attacker to brute force the private value and thus the master secret. When the master secret is known, a
http://security.gentoo.org/glsa/glsa-201310-10.xmlhttp://www.securityfocus.com/bid/53610https://bugs.gentoo.org/show_bug.cgi?id=CVE-2012-2130https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-2130https://exchange.xforce.ibmcloud.com/vulnerabilities/75726https://security-tracker.debian.org/tracker/CVE-2012-2130http://security.gentoo.org/glsa/glsa-201310-10.xmlhttp://www.securityfocus.com/bid/53610https://bugs.gentoo.org/show_bug.cgi?id=CVE-2012-2130https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-2130https://exchange.xforce.ibmcloud.com/vulnerabilities/75726https://security-tracker.debian.org/tracker/CVE-2012-2130
2019-12-06
Published