SB2017110504 - Carry propagation issue in openssl (Alpine package)
Published: November 5, 2017
Security Bulletin ID
SB2017110504
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Carry propagation issue (CVE-ID: CVE-2017-3736)
The vulnerability allows a remote attacker to decrypt data.The vulnerability exists due to carry propagating bug in the x86_64 Montgomery squaring procedure (bn_sqrx8x_internal). A remote attacker can decrypt encrypted data. The vulnerability affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=d2d350f8a099c9ed303f00888e05626662e5c7f6
- https://git.alpinelinux.org/aports/commit/?id=4a8e032821bd6376b9019298b0bea706aa7dd8d4
- https://git.alpinelinux.org/aports/commit/?id=5dc813213f30ce0dc4c05ef71bd1fecf0e03c6ed
- https://git.alpinelinux.org/aports/commit/?id=7acb0c2046e07d331c7d7ab9b1e2eb0c98a03187
- https://git.alpinelinux.org/aports/commit/?id=c57b41c34309ede6b832e2edc306f6ab14a5d78c