Vulnerability name: OpenSSL ECC subsystem encryption Vulnerability
Release date:
Last Updated:
Hazard level: medium risk
Vulnerability Type: Encryption
Threat Type: Remote
CVE No.: CVE-2011-1945
OpenSSL is an open-source SSL implementation that implements high-strength encryption for network communication. It is widely used in various network applications.
When the ECDHE_ECDSA cipher suite uses the Elliptic Curve Digital Signature Algorithm (ECDSA) Algorithm, the OpenSSL 1.0.0d and earlier versions of the elliptic curve cryptography (ECC) subsystem did not correctly implement the Curve represented by binary fields. Attackers can use timed attacks and Lattice (dot matrix) computing to determine the private key.
Currently, the vendor has released an upgrade patch to fix this security issue. Obtain the patch link:
Http://www.openssl.org/source/