5
CVSSv2

CVE-2015-8618

Published: 27/01/2016 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Int.Exp Montgomery code in the math/big library in Go 1.5.x prior to 1.5.3 mishandles carry propagation and produces incorrect output, which makes it easier for malicious users to obtain private RSA keys via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse leap 42.1

golang go 1.5.1

golang go 1.5.2

golang go 1.5

Vendor Advisories

Debian Bug report logs - #809168 golang: CVE-2015-8618: Carry propagation in IntExp Montgomery code in math/big library Package: src:golang; Maintainer for src:golang is Go Compiler Team <team+go-compiler@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 27 Dec 2015 19:18:01 UTC S ...
The IntExp Montgomery code in the math/big library in Go 15x before 153 mishandles carry propagation and produces incorrect output, which makes it easier for attackers to obtain private RSA keys via unspecified vectors ...