CVE-2013-5915: Medium severity polarssl vulnerability
The RSA-CRT implementation in PolarSSL before 1.2.9 does not properly perform Montgomery multiplication, which might allow remote attackers to conduct a timing side-channel attack and retrieve RSA private keys.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5915?
CVE-2013-5915 is classified as a medium severity vulnerability due to potential exposure of RSA private keys via timing side-channel attacks.
How do I fix CVE-2013-5915?
To fix CVE-2013-5915, upgrade PolarSSL to version 1.2.9 or later, which contains the necessary security patches.
What versions of PolarSSL are affected by CVE-2013-5915?
CVE-2013-5915 affects PolarSSL versions prior to 1.2.9, including versions 0.10.0 through 1.2.8.
What types of attacks can exploit CVE-2013-5915?
CVE-2013-5915 can be exploited through remote timing side-channel attacks that may lead to the exposure of private RSA keys.
Is CVE-2013-5915 related to any specific cryptographic operations?
CVE-2013-5915 specifically involves vulnerabilities in the RSA-CRT implementation and Montgomery multiplication of PolarSSL.