| Summary | An issue was discovered in wolfSSL before 5.7.0. A safe-error attack via Rowhammer, namely FAULT+PROBE, leads to ECDSA key disclosure. When WOLFSSL_CHECK_SIG_FAULTS is used in signing operations with private ECC keys, such as in server-side TLS connections, the connection is halted if any fault occurs. The success rate in a certain amount of connection requests can be processed via an advanced technique for ECDSA key recovery. |
|---|---|
| Publication Date | Aug. 28, 2024, 4:15 a.m. |
| Registration Date | Aug. 28, 2024, noon |
| Last Update | Aug. 28, 2024, 9:57 p.m. |
| Title | wolfSSL Inc. の wolfSSL における重要な情報のセキュアでない格納に関する脆弱性 |
|---|---|
| Summary | wolfSSL Inc. の wolfSSL には、重要な情報のセキュアでない格納に関する脆弱性が存在します。 |
| Possible impacts | 情報を取得される可能性があります。 |
| Solution | 参考情報を参照して適切な対策を実施してください。 |
| Publication Date | Aug. 27, 2024, midnight |
| Registration Date | March 4, 2025, 1:28 p.m. |
| Last Update | March 4, 2025, 1:28 p.m. |
| wolfSSL Inc. |
| wolfSSL 5.7.2 未満 |
| No | Changed Details | Date of change |
|---|---|---|
| 1 | [2025年03月04日] 掲載 |
March 4, 2025, 1:28 p.m. |