Beveiligingsadvies

CVE-2015-7744

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2016-01-22 15:00:00
Laatst bijgewerkt 2024-08-06 07:58:59
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.