CVE-2017-1000412: Infoleak
Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable to the bellcore attack in the LibTomCrypt code resulting in compromised private RSA key.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-1000412?
CVE-2017-1000412 is a vulnerability in Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older), which allows for the bellcore attack in the LibTomCrypt code, resulting in compromised private RSA key.
How severe is CVE-2017-1000412?
CVE-2017-1000412 has a severity score of 7.5, which is considered high.
Which version of OP-TEE is affected by CVE-2017-1000412?
OP-TEE version 2.4.0 (and older) is affected by CVE-2017-1000412.
How can I fix CVE-2017-1000412?
To fix CVE-2017-1000412, it is recommended to upgrade to a newer version of OP-TEE, such as version 2.5.0 or newer.
Where can I find more information about CVE-2017-1000412?
You can find more information about CVE-2017-1000412 in the official security advisories from OP-TEE and in the GitHub repositories for OP-TEE.