The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.
CVSS Details
- CVSS 3.1 Base Score: 2.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openssl | Jul 30, 2024 | Aug 8, 2007 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 18, 2013 |
| Gentoo Linux | — | Upgrade app-emulation/emul-linux-x86-baselibs.Upgrade dev-libs/openssl. | Oct 30, 2017 | Aug 7, 2007 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 5, 2026 | Aug 8, 2007 |
| Oracle_linux | — | Upgrade opensslUpgrade openssl-perlUpgrade openssl-devel | May 13, 2016 | Aug 8, 2007 |
| Suse | — | Upgrade openssl1Upgrade libopenssl0_9_8Upgrade libopenssl1_0_0Upgrade libopenssl1_0_0-32bitUpgrade opensslUpgrade openssl-docUpgrade openssl1-docUpgrade libopenssl0_9_8-hmacUpgrade libopenssl0_9_8-32bitUpgrade libopenssl0_9_8-x86Upgrade libopenssl0_9_8-hmac-32bitUpgrade libopenssl1-develUpgrade libopenssl-fips-providerUpgrade libopenssl-devel | Aug 9, 2024 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libssl0.9.8 | Nov 8, 2024 | Aug 8, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub