search menu icon-carat-right cmu-wordmark

CERT Coordination Center

RSA key reconstruction vulnerability

Vulnerability Note VU#724968

Original Release Date: 2007-08-01 | Last Revised: 2007-08-28

Overview

Various implementations of RSA may contain a vulnerability that could allow an attacker to retrieve encryption keys.

Description

Some implementations of RSA may contain a vulnerability that could allow a local attacker to retrieve encryption keys.

OpenSSL is a widely used open source implementation of the SSL and TLS protocols. OpenSSL is based on the SSLeay library. OpenSSL provides support for the RSA encryption algorithm. Note that vendors may include a vulnerable version of OpenSSL in web servers, VPN, or other products.

Impact

An attacker could possibly decrypt messages that were encrypted with OpenSSL using RSA algorithm.

Solution

Apply a patch
OpenSSL has released a patch to address this issue. See http://openssl.org/news/patch-CVE-2007-3108.txt for more details. See the systems affected portion of this document for a partial list of other vendors who may be affected.

Vendor Information

724968
 

View all 64 vendors View less vendors


CVSS Metrics

Group Score Vector
Base 0 AV:--/AC:--/Au:--/C:--/I:--/A:--
Temporal 0 E:ND/RL:ND/RC:ND
Environmental 0 CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND

References

Acknowledgements

Thanks to Dr. Onur Aciicmez, Samsung Information Systems America, Samsung Electronics R&D Center, USA, and Prof. Werner Schindler, Bundesamt für Sicherheit in der Informationstechnik (BSI), Germany for reporting this vulnerability.

This document was written by Ryan Giobbi.

Other Information

CVE IDs: CVE-2007-3108
Severity Metric: 1.77
Date Public: 2007-08-02
Date First Published: 2007-08-01
Date Last Updated: 2007-08-28 14:18 UTC
Document Revision: 27

Sponsored by CISA.