CVE-2011-4354

Description

crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE cipher suites, uses an incorrect modular reduction algorithm in its implementation of the P-256 and P-384 NIST elliptic curves, which allows remote attackers to obtain the private key of a TLS server via multiple handshake attempts.

Risk Information

Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
0.226

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2011-4354,CVE-2011-5095 are affected in OpenSSL 0.9.8Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.1cWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.2bWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.3Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.3aWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.4Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.5Windows
Vulnerabilities CVE-2011-4354 are affected in OpenSSL 0.9.5.beta1Windows
Vulnerabilities CVE-2011-4354 are affected in OpenSSL 0.9.5.beta2Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.5aWindows
Vulnerabilities CVE-2011-4354 are affected in OpenSSL 0.9.5a.beta1Windows
Vulnerabilities CVE-2011-4354 are affected in OpenSSL 0.9.5a.beta2Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6Windows
Vulnerabilities CVE-2011-4354 are affected in OpenSSL 0.9.6.beta1Windows
Vulnerabilities CVE-2011-4354 are affected in OpenSSL 0.9.6.beta2Windows
Vulnerabilities CVE-2011-4354 are affected in OpenSSL 0.9.6.beta3Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6aWindows
Vulnerabilities CVE-2011-4354 are affected in OpenSSL 0.9.6a.beta1Windows
Vulnerabilities CVE-2011-4354 are affected in OpenSSL 0.9.6a.beta2Windows
Vulnerabilities CVE-2011-4354 are affected in OpenSSL 0.9.6a.beta3Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6bWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6cWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6dWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6eWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6fWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6gWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6hWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6iWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6jWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6kWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6lWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6mWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7Windows
Vulnerabilities CVE-2011-4354 are affected in OpenSSL 0.9.7.beta1Windows
Vulnerabilities CVE-2011-4354 are affected in OpenSSL 0.9.7.beta2Windows
Vulnerabilities CVE-2011-4354 are affected in OpenSSL 0.9.7.beta3Windows
Vulnerabilities CVE-2011-4354 are affected in OpenSSL 0.9.7.beta4Windows
Vulnerabilities CVE-2011-4354 are affected in OpenSSL 0.9.7.beta5Windows
Vulnerabilities CVE-2011-4354 are affected in OpenSSL 0.9.7.beta6Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7aWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7bWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7cWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7dWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7eWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7fWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7gWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7hWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7iWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7jWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7kWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7lWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7mWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8aWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8bWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8cWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8dWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8eWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8fWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8gWindows
openssl security update(DSA-3500-1) openssl_1.0.1e-2+deb7u20_i386.debLinux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234