CVE-2015-7744
published 2016-01-22CVE-2015-7744: wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key…
PriorityP336medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
5.03%
91.3th percentile
wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wolfssl | < wolfssl 3.9.10+dfsg-1 (bookworm) | wolfssl 3.9.10+dfsg-1 (bookworm) |
| mariadb | mariadb | >= 10.0.0 < 10.0.22 | 10.0.22 |
| mariadb | mariadb | >= 10.1.0 < 10.1.9 | 10.1.9 |
| mariadb | mariadb | >= 5.5.0 < 5.5.46 | 5.5.46 |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| wolfssl | wolfssl | < 3.6.8 | 3.6.8 |
| wolfssl | wolfssl | >= 0 < 3.9.10+dfsg-1 | 3.9.10+dfsg-1 |
| wolfssl | wolfssl | >= 0 < 3.9.10+dfsg-1 | 3.9.10+dfsg-1 |
| wolfssl | wolfssl | >= 0 < 3.9.10+dfsg-1 | 3.9.10+dfsg-1 |
| wolfssl | wolfssl | >= 0 < 3.9.10+dfsg-1 | 3.9.10+dfsg-1 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f7wf-fgwg-64px: wolfSSL (formerly CyaSSL) before 3
ghsa_unreviewed·2022-05-14
CVE-2015-7744 [MEDIUM] GHSA-f7wf-fgwg-64px: wolfSSL (formerly CyaSSL) before 3
wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.
OSV
CVE-2015-7744: wolfSSL (formerly CyaSSL) before 3
osv·2016-01-22·CVSS 5.9
CVE-2015-7744 [MEDIUM] CVE-2015-7744: wolfSSL (formerly CyaSSL) before 3
wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.
Red Hat
wolfSSL: insufficient hardening of RSA-CRT implementation (Oracle MySQL CPU Jan 2016)
vendor_redhat·2015-01-20·CVSS 5.9
CVE-2015-7744 [MEDIUM] CWE-358 wolfSSL: insufficient hardening of RSA-CRT implementation (Oracle MySQL CPU Jan 2016)
wolfSSL: insufficient hardening of RSA-CRT implementation (Oracle MySQL CPU Jan 2016)
wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.
Package: mysql55-mysql (Red Hat Enterprise Linux 5) - Not affected
Package: mysql (Red Hat Enterprise Linux 6) - Not affected
Package: mariadb (Red Hat Enterprise Linux 7) - Not affected
Package: mariadb-galera (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Package: mariadb-galera (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Not aff
Debian
CVE-2015-7744: wolfssl - wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associate...
vendor_debian·2015·CVSS 5.9
CVE-2015-7744 [MEDIUM] CVE-2015-7744: wolfssl - wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associate...
wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.
Scope: local
bookworm: resolved (fixed in 3.9.10+dfsg-1)
bullseye: resolved (fixed in 3.9.10+dfsg-1)
forky: resolved (fixed in 3.9.10+dfsg-1)
sid: resolved (fixed in 3.9.10+dfsg-1)
trixie: resolved (fixed in 3.9.10+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
mariadb: various flaws [fedora-all]
bugzilla·2016-01-25·CVSS 5.9
[MEDIUM] mariadb: various flaws [fedora-all]
mariadb: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
one tracking bug has be
Bugzilla
community-mysql: various flaws [fedora-all]
bugzilla·2016-01-25·CVSS 5.9
[MEDIUM] community-mysql: various flaws [fedora-all]
community-mysql: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
one tracking bu
Bugzilla
mariadb-galera: various flaws [fedora-all]
bugzilla·2016-01-25·CVSS 5.9
[MEDIUM] mariadb-galera: various flaws [fedora-all]
mariadb-galera: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
one tracking bug
Bugzilla
CVE-2015-7744 yaSSL, wolfSSL: insufficient hardening of RSA-CRT implementation (Oracle MySQL CPU Jan 2016)
bugzilla·2016-01-25·CVSS 5.9
CVE-2015-7744 [MEDIUM] CVE-2015-7744 yaSSL, wolfSSL: insufficient hardening of RSA-CRT implementation (Oracle MySQL CPU Jan 2016)
CVE-2015-7744 yaSSL, wolfSSL: insufficient hardening of RSA-CRT implementation (Oracle MySQL CPU Jan 2016)
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption). Supported versions that are affected are 5.5.45 and earlier and 5.6.26 and earlier. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data.
External References:
http://www.oracle.com/technetwork/topics/security/cpujan2016verbose-2367956.html
Discussion:
Created mariadb tracking bugs for this issue:
Affects: fedora-all [bug 1301518]
---
Created community-mysql tracking bugs for this issue:
Affe
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00016.htmlhttp://wolfssl.com/wolfSSL/Docs-wolfssl-changelog.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.securitytracker.com/id/1034708https://people.redhat.com/~fweimer/rsa-crt-leaks.pdfhttps://securityblog.redhat.com/2015/09/02/factoring-rsa-keys-with-tls-perfect-forward-secrecy/https://wolfssl.com/wolfSSL/Blog/Entries/2015/9/17_Two_Vulnerabilities_Recently_Found%2C_An_Attack_on_RSA_using_CRT_and_DoS_Vulnerability_With_DTLS.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00016.htmlhttp://wolfssl.com/wolfSSL/Docs-wolfssl-changelog.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.securitytracker.com/id/1034708https://people.redhat.com/~fweimer/rsa-crt-leaks.pdfhttps://securityblog.redhat.com/2015/09/02/factoring-rsa-keys-with-tls-perfect-forward-secrecy/https://wolfssl.com/wolfSSL/Blog/Entries/2015/9/17_Two_Vulnerabilities_Recently_Found%2C_An_Attack_on_RSA_using_CRT_and_DoS_Vulnerability_With_DTLS.html
2016-01-22
Published