CVE-2020-15309: Race Condition
An issue was discovered in wolfSSL before 4.5.0, when single precision is not employed. Local attackers can conduct a cache-timing attack against public key operations. These attackers may already have obtained sensitive information if the affected system has been used for private key operations (e.g., signing with a private key).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-15309?
CVE-2020-15309 is a vulnerability in wolfSSL before version 4.5.0 that allows local attackers to conduct a cache-timing attack against public key operations.
How does CVE-2020-15309 affect wolfSSL?
CVE-2020-15309 affects wolfSSL before version 4.5.0 and can be exploited by local attackers to conduct a cache-timing attack.
What is the severity of CVE-2020-15309?
CVE-2020-15309 has a severity level of high.
How can I fix CVE-2020-15309?
To fix CVE-2020-15309, you should update wolfSSL to version 4.5.0 or later.
What is a cache-timing attack?
A cache-timing attack is a method where an attacker tracks the time it takes to access certain cache locations, allowing them to infer sensitive information.