crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE cipher suites, uses an incorrect modular reduction algorithm in its implementation of the P-256 and P-384 NIST elliptic curves, which allows remote attackers to obtain the private key of a TLS server via multiple handshake attempts.
CVSS Details
- CVSS 3.1 Base Score: 4.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openssl | Jul 30, 2024 | Jan 27, 2012 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 5, 2026 | Jan 27, 2012 |
| Suse | — | Upgrade libopenssl0_9_8-hmac-32bitUpgrade libopenssl0_9_8-hmacUpgrade opensslUpgrade libopenssl0_9_8-32bitUpgrade libopenssl-develUpgrade libopenssl0_9_8-x86Upgrade openssl-docUpgrade libopenssl0_9_8 | Aug 9, 2024 | Jul 9, 2013 |
| Ubuntu | — | Upgrade opensslUpgrade libssl0.9.8Upgrade libssl1.0.0 | Nov 8, 2024 | Jan 27, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub