First published: Thu Dec 07 2017(Updated: )
OpenSSL could allow a remote attacker to obtain sensitive information, caused by an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. An attacker could exploit this vulnerability to obtain information about the private key. Note: In order to exploit this vulnerability, the server would have to share the DH1024 private key among multiple clients, which is no longer an option since CVE-2016-0701.
Credit: openssl-security@openssl.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenSSL OpenSSL | =1.0.2 | |
OpenSSL OpenSSL | =1.0.2-beta1 | |
OpenSSL OpenSSL | =1.0.2-beta2 | |
OpenSSL OpenSSL | =1.0.2-beta3 | |
OpenSSL OpenSSL | =1.0.2a | |
OpenSSL OpenSSL | =1.0.2b | |
OpenSSL OpenSSL | =1.0.2c | |
OpenSSL OpenSSL | =1.0.2d | |
OpenSSL OpenSSL | =1.0.2e | |
OpenSSL OpenSSL | =1.0.2f | |
OpenSSL OpenSSL | =1.0.2g | |
OpenSSL OpenSSL | =1.0.2h | |
OpenSSL OpenSSL | =1.0.2i | |
OpenSSL OpenSSL | =1.0.2j | |
OpenSSL OpenSSL | =1.0.2k | |
OpenSSL OpenSSL | =1.0.2l | |
OpenSSL OpenSSL | =1.0.2m | |
OpenSSL OpenSSL | =1.1.0 | |
OpenSSL OpenSSL | =1.1.0a | |
OpenSSL OpenSSL | =1.1.0b | |
OpenSSL OpenSSL | =1.1.0c | |
OpenSSL OpenSSL | =1.1.0d | |
OpenSSL OpenSSL | =1.1.0e | |
OpenSSL OpenSSL | =1.1.0f | |
OpenSSL OpenSSL | =1.1.0g | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Nodejs Node.js | >=4.0.0<=4.1.2 | |
Nodejs Node.js | >=4.2.0<4.8.7 | |
Nodejs Node.js | >=6.0.0<=6.8.1 | |
Nodejs Node.js | >=6.9.0<6.12.2 | |
Nodejs Node.js | >=8.0.0<=8.8.1 | |
Nodejs Node.js | >=8.9.0<8.9.3 | |
Nodejs Node.js | >=9.0.0<9.2.1 | |
debian/openssl | 1.1.1n-0+deb10u3 1.1.1n-0+deb10u6 1.1.1w-0+deb11u1 1.1.1n-0+deb11u5 3.0.11-1~deb12u2 3.1.4-2 | |
redhat/openssl | <1.0.2 | 1.0.2 |
<=10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3738 is a vulnerability in OpenSSL that could allow a remote attacker to obtain sensitive information caused by an overflow bug in the AVX2 Montgomery multiplication procedure.
Versions 1.0.2 up to and excluding 1.1.0 of OpenSSL, as well as certain versions of Node.js and IBM Security Verify Governance, are affected by CVE-2017-3738.
The severity of CVE-2017-3738 is medium, with a CVSS score of 5.9.
No, analysis suggests that attacks against RSA and DSA as a result of this vulnerability would be very difficult to perform and are not believed likely.
You can find more information about CVE-2017-3738 on the Red Hat website: [link1], [link2], [link3].