[FREEBSD:1AAAA5C6-804D-11EC-8BE6-D4C9EF517024] OpenSSL -- BN_mod_exp incorrect results on MIPS
Severity
Medium
Affected Packages
3
CVEs
1
The OpenSSL project reports:
BN_mod_exp may produce incorrect results on MIPS (Moderate)
There is a carry propagation bug in the MIPS32 and MIPS64 squaring
procedure. Many EC algorithms are affected, including some of the
TLS 1.3 default curves. Impact was not analyzed in detail, because the
pre-requisites for attack are considered unlikely and include reusing
private keys. Analysis suggests that attacks against RSA and DSA as a
result of this defect would be very difficult to perform and are not
believed likely. Attacks against DH are considered just feasible
(although very difficult) because most of the work necessary to deduce
information about a private key may be performed offline. The amount
of resources required for such an attack would be significant.
However, for an attack on TLS to be meaningful, the server would have
to share the DH private key among multiple clients, which is no longer
an option since CVE-2016-0701.
Package | Affected Version |
---|---|
pkg:freebsd/openssl-quictls | < 3.0.1 |
pkg:freebsd/openssl-devel | < 3.0.1 |
pkg:freebsd/openssl | < 1.1.1m,1 |
- ID
- FREEBSD:1AAAA5C6-804D-11EC-8BE6-D4C9EF517024
- Severity
- medium
- Severity from
- CVE-2021-4160
- URL
- http://vuxml.freebsd.org/freebsd/1aaaa5c6-804d-11ec-8be6-d4c9ef517024.html
- Published
-
2022-01-28T00:00:00
(2 years ago) - Modified
-
2022-01-28T00:00:00
(2 years ago) - Rights
- FreeBSD VuXML Security Team
- Other Advisories
Source | # ID | Name | URL |
---|---|---|---|
FreeBSD VuXML | https://www.openssl.org/news/secadv/20220128.txt |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:freebsd/openssl-quictls | openssl-quictls | < 3.0.1 | ||||
Affected | pkg:freebsd/openssl-devel | openssl-devel | < 3.0.1 | ||||
Affected | pkg:freebsd/openssl | openssl | < 1.1.1m,1 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |