Information disclosure in OpenSSL - CVE-2015-3193
Published: November 30, -0001 / Updated: May 11, 2018
Vulnerability identifier: #VU2765
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-3193
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The weakness exists in the Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl on the x86_64 platform, as used by the BN_mod_exp function, due to mishandling of carry propagation and producing incorrect output. A remote attacker can gain potentially sensitive private-key information via an attack against use of a (1) Diffie-Hellman (DH) or (2) Diffie-Hellman Ephemeral (DHE) ciphersuite.
The weakness exists in the Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl on the x86_64 platform, as used by the BN_mod_exp function, due to mishandling of carry propagation and producing incorrect output. A remote attacker can gain potentially sensitive private-key information via an attack against use of a (1) Diffie-Hellman (DH) or (2) Diffie-Hellman Ephemeral (DHE) ciphersuite.
Affected software
OpenSSL
Arch Linux
Amazon Linux AMI
SUSE Linux
Slackware Linux
Fedora
SnapDrive for Unix
SnapDrive for Windows
openssl
openssl-solibs
FOS Firmware
Arch Linux
Amazon Linux AMI
SUSE Linux
Slackware Linux
Fedora
SnapDrive for Unix
SnapDrive for Windows
openssl
openssl-solibs
FOS Firmware
How to mitigate CVE-2015-3193
Update to version 1.0.2e.
SnapDrive for Unix - update to 5.3.1
SnapDrive for Windows - update to 7.1.4
openssl - addressed in versions 0.9.8zh, 1.0.1q
openssl-solibs - addressed in versions 0.9.8zh, 1.0.1q
openssl - update to 1.0.2e-1.fc23
FOS Firmware - update to 7.4.1c
SnapDrive for Windows - update to 7.1.4
openssl - addressed in versions 0.9.8zh, 1.0.1q
openssl-solibs - addressed in versions 0.9.8zh, 1.0.1q
openssl - update to 1.0.2e-1.fc23
FOS Firmware - update to 7.4.1c
External References
Related Security Bulletins
- Arch Linux update for lib32-openssl
- Arch Linux update for openssl
- Amazon Linux AMI update for openssl
- OpenSUSE Linux update for openssl
- SUSE Linux update for openssl
- Slackware Linux update for bind
- Multiple vulnerabilities in N series Products
- Multiple vulnerabilities in IBM b-type SAN switches and directors
- Slackware Linux update for openssl
- Fedora 23 update for openssl