CVE-2013-5915

The RSA-CRT implementation in PolarSSL before 1.2.9 does not properly perform Montgomery multiplication, which might allow remote attackers to conduct a timing side-channel attack and retrieve RSA private keys.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
VendorProductVersion
polarsslpolarssl
𝑥
≤ 1.2.8
polarsslpolarssl
0.10.0
polarsslpolarssl
0.10.1
polarsslpolarssl
0.11.0
polarsslpolarssl
0.11.1
polarsslpolarssl
0.12.0
polarsslpolarssl
0.12.1
polarsslpolarssl
0.13.1
polarsslpolarssl
0.14.0
polarsslpolarssl
0.14.2
polarsslpolarssl
0.14.3
polarsslpolarssl
0.99:pre1
polarsslpolarssl
0.99:pre3
polarsslpolarssl
0.99:pre4
polarsslpolarssl
0.99:pre5
polarsslpolarssl
1.0.0
polarsslpolarssl
1.1.0
polarsslpolarssl
1.1.0:rc0
polarsslpolarssl
1.1.0:rc1
polarsslpolarssl
1.1.1
polarsslpolarssl
1.1.2
polarsslpolarssl
1.1.3
polarsslpolarssl
1.1.4
polarsslpolarssl
1.1.5
polarsslpolarssl
1.1.6
polarsslpolarssl
1.1.8
polarsslpolarssl
1.2.0
polarsslpolarssl
1.2.1
polarsslpolarssl
1.2.2
polarsslpolarssl
1.2.3
polarsslpolarssl
1.2.4
polarsslpolarssl
1.2.5
polarsslpolarssl
1.2.6
polarsslpolarssl
1.2.7
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mbedtls
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
dne
trusty
dne
precise
dne
polarssl
zesty
dne
yakkety
dne
xenial
dne
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
dne
saucy
ignored
raring
ignored
quantal
ignored
precise
ignored
lucid
ignored
Common Weakness Enumeration