First published: Tue Jun 05 2018(Updated: )
Some implementations in Intel Integrated Performance Primitives Cryptography Library before version 2018 U3.1 do not properly ensure constant execution time.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Integrated Performance Primitives | <2018_u3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3691 is a vulnerability in Intel Integrated Performance Primitives Cryptography Library that allows for improper execution time.
The severity of CVE-2018-3691 is medium with a CVSS score of 4.7.
CVE-2018-3691 affects versions of Intel Integrated Performance Primitives Cryptography Library before version 2018 U3.1.
To fix CVE-2018-3691, update Intel Integrated Performance Primitives Cryptography Library to version 2018 U3.1 or later.
You can find more information about CVE-2018-3691 in the Intel Security Center Advisory at https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00106.html.