CVE-2017-3736Sensitive Information Exposure in Openssl

Severity
6.5MEDIUMNVD
OSV5.3
EPSS
7.1%
top 8.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 2
Latest updateMay 14

Description

There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

NVDopenssl/openssl1.0.21.0.2m+1
Debianopenssl/openssl< 1.1.0g-1+3
Ubuntuopenssl/openssl< 1.0.1f-1ubuntu2.23+1
CVEListV5openssl_software_foundation/openssl1.0.2 - 1.0.2l, 1.1.0 - 1.1.0f+1

Patches

🔴Vulnerability Details

4
GHSA
GHSA-72w7-9ghx-p5pg: There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 12022-05-14
OSV
openssl vulnerabilities2017-11-06
CVEList
CVE-2017-3736: There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 12017-11-02
OSV
CVE-2017-3736: There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 12017-11-02

📋Vendor Advisories

4
BSD
FreeBSD-SA-17:11.openssl: OpenSSL multiple vulnerabilities2017-11-29
Ubuntu
OpenSSL vulnerabilities2017-11-06
Red Hat
openssl: bn_sqrx8x_internal carry bug on x86_642017-11-02
Debian
CVE-2017-3736: openssl - There is a carry propagating bug in the x86_64 Montgomery squaring procedure in ...2017

💬Community

3
Bugzilla
CVE-2017-3736 openssl: bn_sqrx8x_internal carry bug on x86_642017-11-03
Bugzilla
CVE-2017-3735 CVE-2017-3736 openssl: various flaws [fedora-all]2017-08-29
Bugzilla
CVE-2017-3735 CVE-2017-3736 mingw-openssl: various flaws [fedora-all]2017-08-29
CVE-2017-3736 — Sensitive Information Exposure | cvebase