First published: Tue Jan 02 2018(Updated: )
Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable a timing attack in the Montgomery parts of libMPA in OP-TEE resulting in a compromised private RSA key.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linaro OP-TEE | <=2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000413 is a vulnerability found in Linaro's open source TEE solution called OP-TEE, version 2.4.0 and older, which is susceptible to a timing attack in the Montgomery parts of libMPA in OP-TEE resulting in a compromised private RSA key.
The severity of CVE-2017-1000413 vulnerability is medium, with a severity value of 5.9.
CVE-2017-1000413 affects Linaro's open source TEE solution called OP-TEE, specifically version 2.4.0 and older.
To fix CVE-2017-1000413, it is recommended to update OP-TEE to a version newer than 2.4.0.
More information about CVE-2017-1000413 can be found on the following references: [1] [2] [3].