CVE-2011-4354: Medium severity openssl vulnerability

Published Nov 28, 2011
·
Updated

crypto/bn/bnnist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE cipher suites, uses an incorrect modular reduction algorithm in its implementation of the P-256 and P-384 NIST elliptic curves, which allows remote attackers to obtain the private key of a TLS server via multiple handshake attempts.

Other sources

It was reported that OpenSSL 0.9.8g (only in the 32-bit build) was vulnerable to a bug where, in extremely rare instances, the bug would cause incorrect computation of finite field operations when using NIST elliptic curves P-256 or P-384. This flaw could allow for the retrieval of a TLS server's private key. A paper was published [1] describing the attack.

There are some very specific pre-requisites for a successful attack:

- OpenSSL 0.9.8g (32-bit build) - use of NIST elliptic curve P-256 and/or P-384 - the use of ECDH family ciphers and/or the use of ECDHE family ciphers and the lack of SSLOPSINGLEECDHUSE context option

This bug is corrected in OpenSSL >= 0.9.8h and does not affect earlier versions of OpenSSL than 0.9.8g. A series of patches [2] fix this upstream (starting with r.1.15).

[1] http://eprint.iacr.org/2011/633 [2] http://cvs.openssl.org/rlog?f=openssl%2Fcrypto%2Fbn%2Fbnnist.c

Red Hat

Affected Software

59 affected components
OpenSSL OpenSSL=0.9.6a-beta1
OpenSSL OpenSSL=0.9.7-beta5
OpenSSL OpenSSL=0.9.5
OpenSSL OpenSSL=0.9.8b
OpenSSL OpenSSL=0.9.8
OpenSSL OpenSSL=0.9.8d
OpenSSL OpenSSL=0.9.6l
OpenSSL OpenSSL=0.9.7-beta4
OpenSSL OpenSSL=0.9.7k
OpenSSL OpenSSL=0.9.7-beta2
OpenSSL OpenSSL=0.9.6b
OpenSSL OpenSSL=0.9.5-beta1
OpenSSL OpenSSL=0.9.6c
OpenSSL OpenSSL=0.9.7h
OpenSSL OpenSSL=0.9.4
OpenSSL OpenSSL=0.9.1c
OpenSSL OpenSSL=0.9.7c
OpenSSL OpenSSL=0.9.6h
OpenSSL OpenSSL=0.9.7
OpenSSL OpenSSL=0.9.6m
OpenSSL OpenSSL=0.9.7i
OpenSSL OpenSSL=0.9.7b
OpenSSL OpenSSL=0.9.7j
OpenSSL OpenSSL=0.9.2b
OpenSSL OpenSSL=0.9.8e
OpenSSL OpenSSL=0.9.8f
OpenSSL OpenSSL=0.9.5-beta2
OpenSSL OpenSSL=0.9.8a
OpenSSL OpenSSL=0.9.6-beta1
OpenSSL OpenSSL=0.9.7l
OpenSSL OpenSSL=0.9.6i
OpenSSL OpenSSL=0.9.5a-beta1
OpenSSL OpenSSL=0.9.7g
OpenSSL OpenSSL=0.9.6e
OpenSSL OpenSSL=0.9.7-beta6
OpenSSL OpenSSL=0.9.6a-beta3
OpenSSL OpenSSL=0.9.6j
OpenSSL OpenSSL=0.9.7a
OpenSSL OpenSSL=0.9.6a-beta2
OpenSSL OpenSSL=0.9.3a
OpenSSL OpenSSL=0.9.6f
OpenSSL OpenSSL=0.9.7-beta3
OpenSSL OpenSSL=0.9.7m
OpenSSL OpenSSL=0.9.7f
OpenSSL OpenSSL=0.9.6-beta2
OpenSSL OpenSSL<=0.9.8g
OpenSSL OpenSSL=0.9.6-beta3
OpenSSL OpenSSL=0.9.6
OpenSSL OpenSSL=0.9.7e
OpenSSL OpenSSL=0.9.6a
OpenSSL OpenSSL=0.9.6k
OpenSSL OpenSSL=0.9.6d
OpenSSL OpenSSL=0.9.7-beta1
OpenSSL OpenSSL=0.9.6g
OpenSSL OpenSSL=0.9.7d
OpenSSL OpenSSL=0.9.3
OpenSSL OpenSSL=0.9.5a
OpenSSL OpenSSL=0.9.5a-beta2
OpenSSL OpenSSL=0.9.8c

Event History

Nov 28, 2011
Data Sourced
10:55 PM
DescriptionSeverityAffected Software
Jan 27, 2012
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2011-4354?

CVE-2011-4354 has been classified as a moderate severity vulnerability due to its potential impact on secure communications.

2

How do I fix CVE-2011-4354?

To fix CVE-2011-4354, upgrade OpenSSL to version 0.9.8h or later on affected systems.

3

What impact does CVE-2011-4354 have on affected systems?

CVE-2011-4354 might allow an attacker to exploit weaknesses in the ECDH and ECDHE cipher suites leading to compromised cryptographic keys.

4

Which OpenSSL versions are affected by CVE-2011-4354?

CVE-2011-4354 affects OpenSSL versions before 0.9.8h on 32-bit platforms.

5

In what products is CVE-2011-4354 known to be a vulnerability?

CVE-2011-4354 is known to affect products that utilize vulnerable versions of OpenSSL, including stunnel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203