2.6
CVSSv2

CVE-2011-1945

Published: 31/05/2011 Updated: 06/06/2013
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 232
Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N

Vulnerability Summary

The elliptic curve cryptography (ECC) subsystem in OpenSSL 1.0.0d and previous versions, when the Elliptic Curve Digital Signature Algorithm (ECDSA) is used for the ECDHE_ECDSA cipher suite, does not properly implement curves over binary fields, which makes it easier for context-dependent malicious users to determine private keys via a timing attack and a lattice calculation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openssl openssl 0.9.3a

openssl openssl 0.9.4

openssl openssl 0.9.6

openssl openssl 0.9.6i

openssl openssl 1.0.0

openssl openssl 0.9.6h

openssl openssl 0.9.7

openssl openssl 0.9.8h

openssl openssl 0.9.8m

openssl openssl 0.9.8i

openssl openssl 0.9.7h

openssl openssl 0.9.7i

openssl openssl 0.9.8e

openssl openssl 0.9.8c

openssl openssl 0.9.5

openssl openssl 0.9.5a

openssl openssl 0.9.6a

openssl openssl 0.9.6g

openssl openssl 0.9.6e

openssl openssl 0.9.6d

openssl openssl 0.9.6k

openssl openssl 0.9.6j

openssl openssl 0.9.3

openssl openssl 0.9.2b

openssl openssl 1.0.0a

openssl openssl 0.9.7d

openssl openssl 0.9.7e

openssl openssl 0.9.8

openssl openssl 0.9.8a

openssl openssl 0.9.7j

openssl openssl 1.0.0b

openssl openssl 1.0.0c

openssl openssl 0.9.6f

openssl openssl 0.9.8g

openssl openssl 0.9.6m

openssl openssl 0.9.6l

openssl openssl 0.9.1c

openssl openssl 0.9.8l

openssl openssl 0.9.8p

openssl openssl 0.9.7a

openssl openssl 0.9.7b

openssl openssl 0.9.7c

openssl openssl 0.9.7k

openssl openssl 0.9.7l

openssl openssl

openssl openssl 0.9.6c

openssl openssl 0.9.6b

openssl openssl 0.9.8f

openssl openssl 0.9.8n

openssl openssl 0.9.8o

openssl openssl 0.9.8k

openssl openssl 0.9.7m

openssl openssl 0.9.8j

openssl openssl 0.9.7f

openssl openssl 0.9.7g

openssl openssl 0.9.8b

openssl openssl 0.9.8d

Vendor Advisories

Multiple vulnerabilities exist in OpenSSL that could expose sensitive information or cause applications to crash ...
Several fraudulent SSL certificates have been found in the wild issued by the DigiNotar Certificate Authority, obtained through a security compromise of said company After further updates on this incident, it has been determined that all of DigiNotar's signing certificates can no longer be trusted Debian, like other software distributors and vend ...