CVE-2015-7744
MEDIUMwolfSSL < 3.6.8 - Remote Private RSA Key Exposure via Lenstra Attack
Title source: llmDescription
wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.
References (9)
Core 9
Core References
Mailing List, Third Party Advisory vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.html
Broken Link, Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1034708
Release Notes, Vendor Advisory x_refsource_confirm
http://wolfssl.com/wolfSSL/Docs-wolfssl-changelog.html
Exploit, Third Party Advisory x_refsource_misc
https://people.redhat.com/~fweimer/rsa-crt-leaks.pdf
Vendor Advisory x_refsource_confirm
http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
Third Party Advisory x_refsource_confirm
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
Vendor Advisory x_refsource_confirm
https://wolfssl.com/wolfSSL/Blog/Entries/2015/9/17_Two_Vulnerabilities_Recently_Found%2C_An_Attack_on_RSA_using_CRT_and_DoS_Vulnerability_With_DTLS.html
Exploit, Third Party Advisory x_refsource_misc
https://securityblog.redhat.com/2015/09/02/factoring-rsa-keys-with-tls-perfect-forward-secrecy/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00016.html
Scores
CVSS v3
5.9
EPSS
0.0268
EPSS Percentile
86.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
Status
published
Products (5)
mariadb/mariadb
5.5.0 - 5.5.46
opensuse/leap
42.1
opensuse/opensuse
13.1
opensuse/opensuse
13.2
wolfssl/wolfssl
< 3.6.8
Published
Jan 22, 2016
Tracked Since
Feb 18, 2026