The elliptic curve cryptography (ECC) subsystem in OpenSSL 1.0.0d and earlier, when the Elliptic Curve Digital Signature Algorithm (ECDSA) is used for the ECDHE_ECDSA cipher suite, does not properly implement curves over binary fields, which makes it easier for context-dependent attackers to determine private keys via a timing attack and a lattice calculation.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Note | — | Apply OS X security update 2013-002Upgrade macOS to the latest version | Aug 28, 2015 | May 31, 2011 |
| Apple Osx Openssl | — | Upgrade macOS to the latest versionApply OS X security update 2013-002 | Jun 20, 2013 | May 31, 2011 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | May 31, 2011 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Oct 30, 2017 | May 31, 2011 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 13, 2015 | May 31, 2011 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 5, 2026 | May 31, 2011 |
| Suse | — | Upgrade libopenssl1_0_0Upgrade openssl-docUpgrade openssl-64bitUpgrade openssl-devel-64bitUpgrade openssl-develUpgrade openssl-32bitUpgrade libopenssl-develUpgrade openssl-x86Upgrade libopenssl1_0_0-32bitUpgrade sap-aio-releaseUpgrade opensslUpgrade openssl-devel-32bit | Dec 12, 2013 | May 31, 2011 |
| Ubuntu | — | Upgrade libssl0.9.8Upgrade opensslUpgrade libssl1.0.0 | Nov 8, 2024 | May 31, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub