Bug 2308608 (CVE-2024-1545) - CVE-2024-1545 WolfSSL: Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL
Summary: CVE-2024-1545 WolfSSL: Fault Injection vulnerability in RsaPrivateDecryption ...
Keywords:
Status: NEW
Alias: CVE-2024-1545
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2308630 2308631
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-08-29 23:30 UTC by OSIDB Bzimport
Modified: 2024-08-30 15:58 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2024-08-29 23:30:32 UTC
Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process to disclose information and escalate privileges via Rowhammer fault injection to the RsaKey structure.


Note You need to log in before you can comment on or make changes to this bug.