First published: Fri Jun 15 2018(Updated: )
LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libtom Libtomcrypt | <=1.18.1 | |
Linaro OP-TEE | <=3.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of LibTomCrypt is CVE-2018-12437.
The severity of CVE-2018-12437 is medium.
CVE-2018-12437 allows a memory-cache side-channel attack on ECDSA signatures, which can expose an ECDSA key to an attacker with access to the local machine or a different virtual machine on the same physical host.
LibTomCrypt versions up to and including 1.18.1, as well as Linaro OP-TEE versions up to and including 3.5.0, are affected by CVE-2018-12437.
The recommended mitigation for CVE-2018-12437 in LibTomCrypt is to apply the latest security patches or updates provided by the software vendor.