First published: Wed Aug 08 2007(Updated: )
The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenSSL OpenSSL | <=0.9.8e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.