CVE-2015-8618: Infoleak
Published Jan 27, 2016
·Updated
The Int.Exp Montgomery code in the math/big library in Go 1.5.x before 1.5.3 mishandles carry propagation and produces incorrect output, which makes it easier for attackers to obtain private RSA keys via unspecified vectors.
Affected Software
4 affected components
openSUSE Leap=42.1
Golang Go=1.5
Golang Go=1.5.1
Golang Go=1.5.2
Remediation
Patch Available
Event History
Jan 27, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8618?
CVE-2015-8618 is considered to have high severity as it can lead to the exposure of private RSA keys.
2
How do I fix CVE-2015-8618?
To fix CVE-2015-8618, upgrade to Go versions 1.5.3 or later.
3
What products are affected by CVE-2015-8618?
Affected products include Go versions 1.5, 1.5.1, 1.5.2, and openSUSE Leap 42.1.
4
What type of attack does CVE-2015-8618 facilitate?
CVE-2015-8618 facilitates attacks that can obtain private RSA keys through specific vulnerabilities.
5
Is the vulnerability CVE-2015-8618 exploitable remotely?
The exploitability of CVE-2015-8618 is dependent on the specific implementation and environment, though it could allow for remote attacks under certain conditions.