wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade mariadb | Aug 30, 2017 | Jan 20, 2016 |
| Debian | — | Upgrade mysql-5.5Upgrade wolfssl | Jul 30, 2024 | Jan 22, 2016 |
| Freebsd | — | Upgrade wolfssl | Dec 10, 2025 | Jan 5, 2016 |
| Mariadb Mariadb | — | Upgrade MariaDB to the latest version | Mar 4, 2025 | Jan 22, 2016 |
| Oracle Solaris | — | Upgrade database/mysql-55 to version 5.5.48-0.175.3.7.0.4.0 on Solaris 11.3Upgrade database/mysql-55/tests to version 5.5.48-0.175.3.7.0.4.0 on Solaris 11.3 | May 29, 2017 | Jan 22, 2016 |
| Oracle_linux | — | Upgrade mariadb-benchUpgrade mariadb-embeddedUpgrade mariadb-develUpgrade mariadbUpgrade mariadb-testUpgrade mariadb-serverUpgrade mariadb-libsUpgrade mariadb-embedded-devel | Apr 7, 2016 | Jan 22, 2016 |
| Suse | — | Upgrade mysql-clientUpgrade libmysql55client18-32bitUpgrade mariadb-toolsUpgrade libmysql55client_r18Upgrade mariadbUpgrade libmysql55client18-x86Upgrade mariadb-errormessagesUpgrade mysqlUpgrade libmysqld-develUpgrade libmysql55client_r18-x86Upgrade libmariadbd19Upgrade libmysql55client_r18-32bitUpgrade libmysql55client18Upgrade libmariadbd-develUpgrade libmysqld19Upgrade mysql-toolsUpgrade mariadb-client | Feb 5, 2016 | Jan 22, 2016 |
| Ubuntu | — | Upgrade mysql-5.5Upgrade percona-xtradb-cluster-5.6Upgrade mariadb-5.5Upgrade mysql-5.6 | Nov 19, 2024 | Jan 22, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub