CVE-2017-1000413: Infoleak
Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable a timing attack in the Montgomery parts of libMPA in OP-TEE resulting in a compromised private RSA key.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-1000413?
CVE-2017-1000413 is a vulnerability found in Linaro's open source TEE solution called OP-TEE, version 2.4.0 and older, which is susceptible to a timing attack in the Montgomery parts of libMPA in OP-TEE resulting in a compromised private RSA key.
How severe is the CVE-2017-1000413 vulnerability?
The severity of CVE-2017-1000413 vulnerability is medium, with a severity value of 5.9.
Which software versions are affected by CVE-2017-1000413?
CVE-2017-1000413 affects Linaro's open source TEE solution called OP-TEE, specifically version 2.4.0 and older.
How can I fix CVE-2017-1000413?
To fix CVE-2017-1000413, it is recommended to update OP-TEE to a version newer than 2.4.0.
Where can I find more information about CVE-2017-1000413?
More information about CVE-2017-1000413 can be found on the following references: [1] [2] [3].