First published: Tue Jan 02 2018(Updated: )
Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable to the bellcore attack in the LibTomCrypt code resulting in compromised private RSA key.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linaro OP-TEE | <=2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000412 is a vulnerability in Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older), which allows for the bellcore attack in the LibTomCrypt code, resulting in compromised private RSA key.
CVE-2017-1000412 has a severity score of 7.5, which is considered high.
OP-TEE version 2.4.0 (and older) is affected by CVE-2017-1000412.
To fix CVE-2017-1000412, it is recommended to upgrade to a newer version of OP-TEE, such as version 2.5.0 or newer.
You can find more information about CVE-2017-1000412 in the official security advisories from OP-TEE and in the GitHub repositories for OP-TEE.