CVE-2011-4354
Published Jan 27, 2012
Last updated 12 years ago
Overview
- Description
- crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE cipher suites, uses an incorrect modular reduction algorithm in its implementation of the P-256 and P-384 NIST elliptic curves, which allows remote attackers to obtain the private key of a TLS server via multiple handshake attempts.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5.8
- Impact score
- 4.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-310
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "9AEAB1A1-9613-449E-BCF4-3DE365582EB0", "versionEndIncluding": "0.9.8g" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.1c:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "738E2D3C-1C7D-4F85-B0DE-608BB5059337" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.2b:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "140B617A-2414-4D1A-98A4-3CA8D76F5122" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.3:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "99EBBB96-8089-4A3C-BD30-9684823B42E5" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.3a:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "3B39A92A-C78D-4007-9FFF-BF37949793F8" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.4:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "A29D0ACA-711C-4E8B-9604-68889E05EE2C" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.5:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "D1CB6460-8A55-4C5E-BEB5-153697A82A47" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.5:beta1:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "F3372BA6-62FD-434F-89EB-11B63114A1E1" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.5:beta2:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "A007DA0C-4269-4E36-9082-097CEB76E65D" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.5a:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "B7B9FF7F-E455-4774-94C2-1A456CA9E732" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.5a:beta1:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "21EB68D7-DFC7-4EE4-A316-6088800885F1" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.5a:beta2:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "4414272F-3D22-4C84-884D-5FB803CC7CC6" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.6:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "392AAE2E-16F7-4454-BD0C-9D850234370C" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.6:beta1:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "CB0A2D5D-019A-4E62-9FC0-663E0866DFE9" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.6:beta2:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "0B4F12DC-85F2-4A7B-B13A-876DEDA1DD2D" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.6:beta3:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "E53DAA27-F643-4129-B0C7-7480C6970A26" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.6a:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "6DAE038E-4051-4B41-960C-7692EF5B1EB1" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.6a:beta1:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "9B929792-45CC-4D23-B598-2759FD9745E5" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.6a:beta2:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "4D38BAC5-5DAC-4D01-8DC1-E220D770FBD0" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.6a:beta3:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "51B2B652-5BAE-4FB2-8A29-8A6024298FEA" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.6b:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "68BCE929-22C4-49AB-A8A4-6D4CE9810538" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.6c:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "454F3308-7579-4A10-9468-B083BAD0F888" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.6d:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "1C844D0A-9CDD-4776-BF63-35D3BFBABC20" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.6e:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "49AADE06-D464-49E3-892C-900F216AD23A" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.6f:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "92D0FD74-AF88-4947-A90F-1CD17D628ABE" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.6g:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "D63F3A33-0E25-4CA0-82F1-51E9A8457A17" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.6h:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "26C8F4C9-3E87-4196-B074-6DEB60ACD4DB" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.6i:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "724B5C08-89FB-4EE6-8710-09AA21955ED2" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.6j:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "A129E1C4-5673-4600-8BEE-315AC8AAE569" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.6k:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "5EA07221-5828-4383-BE25-6CD991047879" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.6l:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "F2FC5631-F631-44A7-B2DC-AA76F4DE186D" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.6m:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "F20B2F90-78FC-413A-9066-3BD5252764A9" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "E7B90CD7-797F-4B4C-9017-3EFB29CAE66B" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7:beta1:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "FF3D7D8E-BDD6-46CA-88A3-81D9E197299B" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7:beta2:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "5603FF96-C5BA-46E4-8586-17ADD67F28C8" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7:beta3:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "A45D0D8B-00EB-445F-B5B9-ABB49684AE0E" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7:beta4:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "53EAA2F9-E32D-4476-959D-1B4F6C07A8FB" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7:beta5:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "2C19BC02-0004-44C2-951D-AE24F992CC72" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7:beta6:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "ABB67EE9-3B97-491F-9A76-7B1F00AAC3F1" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7a:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "F9170AB7-15F2-4D29-9E50-5AF0FF08AA7D" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7b:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "393756F1-E618-44AC-848E-5CEE72332A70" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7c:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "B092333E-EAEC-4194-BB48-3952B1C8D3FB" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7d:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "491A8371-4E99-4AA0-853A-A8C681F8F871" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7e:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "9CC396FC-BB44-4D9D-B86C-AACCAC41C956" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7f:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "65C2EBFE-7DAD-48C9-91B4-734EFF8AAD44" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7g:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "6058CD3A-5957-423D-A5C2-CD19EB465078" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7h:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "A1CE22A9-37AF-4D08-88FE-FCFFA5478B3C" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7i:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "945593B5-7886-464C-A180-36179093F12A" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7j:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "19ED47E7-7265-4E7D-BC9E-9D1A2D570C92" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7k:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "8E80A932-709F-4E7C-8FBD-07AC16BA3576" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7l:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "D5E0635E-7C2B-4A6B-B645-A54548691EA8" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7m:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "7E78DB14-F04C-44E7-BAC3-41CD1640C763" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "B34623C1-9953-4775-B3F6-3313A3168184" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8a:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "863F69F8-E46B-4C9E-835D-A7CECBCD013A" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8b:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "B9F78319-7FA2-452F-8909-C4DD125D3484" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8c:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "13AE346B-7723-4FB9-A14E-5AEA933934BB" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8d:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "7596B2B9-6F2B-4A83-9B29-5D4153936E57" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8e:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "BB25C8AF-BE70-4EEE-A2CC-F3D8FF9A80B0" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8f:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "0B679997-5497-428A-9CBB-28BE6B49EF85" } ], "operator": "OR" } ] } ]