CVE-2017-6076Sensitive Information Exposure in Wolfssl

Severity
5.5MEDIUMNVD
EPSS
0.2%
top 63.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 24
Latest updateMay 14

Description

In versions of wolfSSL before 3.10.2 the function fp_mul_comba makes it easier to extract RSA key information for a malicious user who has access to view cache on a machine.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/wolfssl< wolfssl 3.10.2+dfsg-1 (bookworm)
NVDwolfssl/wolfssl< 3.10.2
Debianwolfssl/wolfssl< 3.10.2+dfsg-1+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8hxw-x3wx-q3hv: In versions of wolfSSL before 32022-05-14
OSV
CVE-2017-6076: In versions of wolfSSL before 32017-02-24

📋Vendor Advisories

1
Debian
CVE-2017-6076: wolfssl - In versions of wolfSSL before 3.10.2 the function fp_mul_comba makes it easier t...2017

💬Community

1
Bugzilla
qt5-qtwebengine: 16 security vulnerabilities2018-03-24
CVE-2017-6076 — Sensitive Information Exposure | cvebase