CVE-2015-7744

wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*

Information

Published : 2016-01-22 15:59

Updated : 2018-10-30 16:27


NVD link : CVE-2015-7744

Mitre link : CVE-2015-7744


JSON object : View

Products Affected

opensuse

  • leap
  • opensuse

wolfssl

  • wolfssl
CWE
CWE-19

Data Processing Errors