CVE-2018-12437: Infoleak
LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of LibTomCrypt?
The vulnerability ID of LibTomCrypt is CVE-2018-12437.
What is the severity of CVE-2018-12437?
The severity of CVE-2018-12437 is medium.
What is the impact of CVE-2018-12437?
CVE-2018-12437 allows a memory-cache side-channel attack on ECDSA signatures, which can expose an ECDSA key to an attacker with access to the local machine or a different virtual machine on the same physical host.
Which software versions are affected by CVE-2018-12437?
LibTomCrypt versions up to and including 1.18.1, as well as Linaro OP-TEE versions up to and including 3.5.0, are affected by CVE-2018-12437.
How do I mitigate the vulnerability in LibTomCrypt?
The recommended mitigation for CVE-2018-12437 in LibTomCrypt is to apply the latest security patches or updates provided by the software vendor.