Back

LOW

openssl: ECDSA private key leak through a remote timing attack

Published May 31, 2011

Description

The elliptic curve cryptography (ECC) subsystem in OpenSSL 1.0.0d and earlier, when the Elliptic Curve Digital Signature Algorithm (ECDSA) is used for the ECDHE_ECDSA cipher suite, does not properly implement curves over binary fields, which makes it easier for context-dependent attackers to determine private keys via a timing attack and a lattice calculation.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of openssl as shipped with Red Hat Enterprise Linux 3, 4, 5, or 6, as they do not include the support for the elliptic curve cryptography.

Metrics

Weaknesses (1)

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 31, 2011
Updated Aug 6, 2024
Reserved May 9, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date May 17, 2011