Description
The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.
Published: 2007-08-08
Score: 1.2 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-1571-1 New openssl packages fix predictable random number generator
EUVD EUVD EUVD-2007-3100 The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.
Ubuntu USN Ubuntu USN USN-522-1 openssl vulnerabilities
References
Link Providers
http://cvs.openssl.org/chngview?cn=16275 cve-icon cve-icon
http://lists.vmware.com/pipermail/security-announce/2008/000002.html cve-icon cve-icon
http://openssl.org/news/patch-CVE-2007-3108.txt cve-icon cve-icon
http://secunia.com/advisories/26411 cve-icon cve-icon
http://secunia.com/advisories/26893 cve-icon cve-icon
http://secunia.com/advisories/27021 cve-icon cve-icon
http://secunia.com/advisories/27078 cve-icon cve-icon
http://secunia.com/advisories/27097 cve-icon cve-icon
http://secunia.com/advisories/27205 cve-icon cve-icon
http://secunia.com/advisories/27330 cve-icon cve-icon
http://secunia.com/advisories/27770 cve-icon cve-icon
http://secunia.com/advisories/27870 cve-icon cve-icon
http://secunia.com/advisories/28368 cve-icon cve-icon
http://secunia.com/advisories/30161 cve-icon cve-icon
http://secunia.com/advisories/30220 cve-icon cve-icon
http://secunia.com/advisories/31467 cve-icon cve-icon
http://secunia.com/advisories/31489 cve-icon cve-icon
http://secunia.com/advisories/31531 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200710-06.xml cve-icon cve-icon
http://support.attachmate.com/techdocs/2374.html cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2007-485.htm cve-icon cve-icon
http://www.bluecoat.com/support/securityadvisories/advisory_openssl_rsa_key_reconstruction_vulnerability cve-icon cve-icon
http://www.debian.org/security/2008/dsa-1571 cve-icon cve-icon
http://www.gentoo.org/security/en/glsa/glsa-200805-07.xml cve-icon cve-icon
http://www.kb.cert.org/vuls/id/724968 cve-icon cve-icon
http://www.kb.cert.org/vuls/id/RGII-74KLP3 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:193 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0813.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0964.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-1003.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/476341/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/485936/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/486859/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/25163 cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2008-0001.html cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2008-0013.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2759 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/4010 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/0064 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2361 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2362 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2396 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-1613 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-1633 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-3108 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9984 cve-icon cve-icon
https://usn.ubuntu.com/522-1/ cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-3108 cve-icon
History

No history.

Subscriptions

Openssl Openssl
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T14:05:28.268Z

Reserved: 2007-06-07T00:00:00.000Z

Link: CVE-2007-3108

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-08-08T01:17:00.000

Modified: 2026-04-23T00:35:47.467

Link: CVE-2007-3108

cve-icon Redhat

Severity : Moderate

Publid Date: 2007-08-01T00:00:00Z

Links: CVE-2007-3108 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses