Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1301488 - (CVE-2015-7744) CVE-2015-7744 yaSSL, wolfSSL: insufficient hardening of RSA-CRT implementation (Oracle MySQL CPU Jan 2016)
CVE-2015-7744 yaSSL, wolfSSL: insufficient hardening of RSA-CRT implementatio...
Status: CLOSED NOTABUG
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
impact=low,public=20150120,reported=2...
: Security
Depends On:
Blocks: 1301514
  Show dependency treegraph
 
Reported: 2016-01-25 04:05 EST by Martin Prpič
Modified: 2016-10-26 10:13 EDT (History)
27 users (show)

See Also:
Fixed In Version: mysql 5.5.46, mysql 5.6.27, mariadb 5.5.46, mariadb 10.1.9, mariadb 10.0.22, wolfSSL 3.6.8, yaSSL 2.3.8
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-02-08 04:28:43 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Martin Prpič 2016-01-25 04:05:39 EST
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption). Supported versions that are affected are 5.5.45 and earlier and 5.6.26 and earlier. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. 

External References:

http://www.oracle.com/technetwork/topics/security/cpujan2016verbose-2367956.html
Comment 1 Martin Prpič 2016-01-25 04:33:37 EST
Created mariadb tracking bugs for this issue:

Affects: fedora-all [bug 1301518]
Comment 2 Martin Prpič 2016-01-25 04:33:49 EST
Created community-mysql tracking bugs for this issue:

Affects: fedora-all [bug 1301517]
Comment 3 Martin Prpič 2016-01-25 04:34:00 EST
Created mariadb-galera tracking bugs for this issue:

Affects: fedora-all [bug 1301519]
Comment 5 Tomas Hoger 2016-02-08 04:28:43 EST
This actually is not a MySQL flaw, but a flaw in embedded yaSSL library.  Mitre CVE description is:

  wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults
  associated with the Chinese Remainder Theorm (CRT) process when allowing
  ephemeral key exchange without low memory optimizations on a server, which
  makes it easier for remote attackers to obtain private RSA keys by capturing
  TLS handshakes, aka a Lenstra attack.

References:

https://wolfssl.com/wolfSSL/Blog/Entries/2015/9/17_Two_Vulnerabilities_Recently_Found%2C_An_Attack_on_RSA_using_CRT_and_DoS_Vulnerability_With_DTLS.html
https://www.wolfssl.com/wolfSSL/Docs-yassl-changelog.html
https://people.redhat.com/~fweimer/rsa-crt-leaks.pdf
https://securityblog.redhat.com/2015/09/02/factoring-rsa-keys-with-tls-perfect-forward-secrecy/

Issue was fixed in MySQL by updating embedded yaSSL library to version 2.3.8:

https://github.com/mysql/mysql-server/commit/b9768521bdeb1a8069c7b871f4536792b65fd79b

MySQL and MariaDB packages as included in Red Hat products do not use embedded yaSSL library and rather use system OpenSSL.  Therefore, they were not affected by this issue.

Note You need to log in before you can comment on or make changes to this bug.