The DH_check_pub_key function in crypto/dh/dh_check.c in OpenSSL 1.0.2 before 1.0.2f does not ensure that prime numbers are appropriate for Diffie-Hellman (DH) key exchange, which makes it easier for remote attackers to discover a private DH exponent by making multiple handshakes with a peer that chose an inappropriate number, as demonstrated by a number in an X9.42 file.
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openssl | Jul 30, 2024 | Feb 15, 2016 |
| Freebsd | — | Upgrade FreeBSDUpgrade opensslUpgrade mingw32-openssl | Dec 10, 2017 | Jan 28, 2016 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Oct 30, 2017 | Feb 14, 2016 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Feb 15, 2016 | Feb 15, 2016 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4Upgrade library/security/openssl to version 1.0.2.14-0.175.3.28.0.2.0 on Solaris 11.3Upgrade library/security/openssl/openssl-fips-140 to version 2.0.12-0.175.3.28.0.2.0 on Solaris 11.3 | Feb 6, 2018 | Feb 14, 2016 |
| Suse | — | Upgrade opensslUpgrade libopenssl1_0_0Upgrade libopenssl-1_0_0-develUpgrade libopenssl1_1-hmac-32bitUpgrade libopenssl1_1Upgrade openssl-1_0_0Upgrade libopenssl-1_1-devel-32bitUpgrade libopenssl1_1-hmacUpgrade openssl-1_1Upgrade libopenssl-develUpgrade libopenssl10Upgrade libopenssl1_1-32bitUpgrade libopenssl-1_1-devel | Mar 3, 2016 | Feb 14, 2016 |
| Ubuntu | — | Upgrade libssl1.0.0 | Feb 2, 2016 | Jan 28, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub