Back to search
CVE-2016-0701
Published: Feb 15, 2016
Modified: Aug 5, 2024
PUBLISHED
Description
The DH_check_pub_key function in crypto/dh/dh_check.c in OpenSSL 1.0.2 before 1.0.2f does not ensure that prime numbers are appropriate for Diffie-Hellman (DH) key exchange, which makes it easier for remote attackers to discover a private DH exponent by making multiple handshakes with a peer that chose an inappropriate number, as demonstrated by a number in an X9.42 file.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2016-527018d2ff
vendor-advisory
1034849
vdb-entry
GLSA-201601-05
vendor-advisory
82233
vdb-entry
91787
vdb-entry
VU#257823
third-party-advisory
openSUSE-SU-2016:0637
vendor-advisory
USN-2883-1
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now