CVE-2011-4354
Publication date 26 January 2012
Last updated 24 July 2024
Ubuntu priority
crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE cipher suites, uses an incorrect modular reduction algorithm in its implementation of the P-256 and P-384 NIST elliptic curves, which allows remote attackers to obtain the private key of a TLS server via multiple handshake attempts.
Status
Package | Ubuntu Release | Status |
---|---|---|
openssl | ||
Patch details
Package | Patch details |
---|---|
openssl |
References
Related Ubuntu Security Notices (USN)
- USN-1357-1
- OpenSSL vulnerabilities
- 9 February 2012