CVE-2011-4354

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
27/01/2012
Last modified:
11/04/2025

Description

crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE cipher suites, uses an incorrect modular reduction algorithm in its implementation of the P-256 and P-384 NIST elliptic curves, which allows remote attackers to obtain the private key of a TLS server via multiple handshake attempts.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:x86:* 0.9.8g (including)
cpe:2.3:a:openssl:openssl:0.9.1c:*:*:*:*:*:x86:*
cpe:2.3:a:openssl:openssl:0.9.2b:*:*:*:*:*:x86:*
cpe:2.3:a:openssl:openssl:0.9.3:*:*:*:*:*:x86:*
cpe:2.3:a:openssl:openssl:0.9.3a:*:*:*:*:*:x86:*
cpe:2.3:a:openssl:openssl:0.9.4:*:*:*:*:*:x86:*
cpe:2.3:a:openssl:openssl:0.9.5:*:*:*:*:*:x86:*
cpe:2.3:a:openssl:openssl:0.9.5:beta1:*:*:*:*:x86:*
cpe:2.3:a:openssl:openssl:0.9.5:beta2:*:*:*:*:x86:*
cpe:2.3:a:openssl:openssl:0.9.5a:*:*:*:*:*:x86:*
cpe:2.3:a:openssl:openssl:0.9.5a:beta1:*:*:*:*:x86:*
cpe:2.3:a:openssl:openssl:0.9.5a:beta2:*:*:*:*:x86:*
cpe:2.3:a:openssl:openssl:0.9.6:*:*:*:*:*:x86:*
cpe:2.3:a:openssl:openssl:0.9.6:beta1:*:*:*:*:x86:*
cpe:2.3:a:openssl:openssl:0.9.6:beta2:*:*:*:*:x86:*