CVE-2015-3193Sensitive Information Exposure in Software Foundation Openssl

Severity
7.5HIGHNVD
EPSS
35.2%
top 2.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 6
Latest updateMay 17

Description

The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 platform, as used by the BN_mod_exp function, mishandles carry propagation and produces incorrect output, which makes it easier for remote attackers to obtain sensitive private-key information via an attack against use of a (1) Diffie-Hellman (DH) or (2) Diffie-Hellman Ephemeral (DHE) ciphersuite.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

Debianopenssl/openssl< 1.0.2e-1+3
NVDopenssl/openssl5 versions+4
CVEListV5openssl_software_foundation/openssl1.0.2-1.02m, 1.1.0-1.1.0g+1
NVDnodejs/node.js4.2.04.2.3+2

Also affects: Ubuntu Linux 12.04, 14.04, 15.04, 15.10

Patches

🔴Vulnerability Details

4
GHSA
GHSA-8m9h-2gxv-h3m7: The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont52022-05-17
OSV
openssl vulnerabilities2015-12-07
CVEList
CVE-2015-3193: The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont52015-12-06
OSV
CVE-2015-3193: The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont52015-12-06

📋Vendor Advisories

5
Apple
CVE-2015-3193: Xcode 8.12016-10-27
Ubuntu
OpenSSL vulnerabilities2015-12-07
Cisco
Multiple Vulnerabilities in OpenSSL (December 2015) Affecting Cisco Products2015-12-04
Red Hat
OpenSSL: BN_mod_exp may produce incorrect results on x86_642015-12-03
Debian
CVE-2015-3193: openssl - The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenS...2015

💬Community

3
HackerOne
BN_mod_exp may produce incorrect results on x86_64 (CVE-2015-3193)2016-04-12
Bugzilla
CVE-2015-8618 golang: Carry propagation in Int.Exp Montgomery code in math/big library2015-12-21
Bugzilla
CVE-2015-3193 OpenSSL: BN_mod_exp may produce incorrect results on x86_642015-12-04
CVE-2015-3193 — Sensitive Information Exposure | cvebase