VDB

CVE-2017-3732

CVE-2017-3732 PUBLISHED

There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL 1.0.2 before 1.0.2k and 1.1.0 before 1.1.0d. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. For example this can occur by default in OpenSSL DHE based SSL/TLS ciphersuites. Note: This issue is very similar to CVE-2015-3193 but must be treated as a separate problem.

EPSS 5.18% · 90.1th percentile

Risk Scores

EPSS Score
5.18%
90.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSopenssl0, 1.0.2d-0ubuntu1, 1.0.2e-1ubuntu1

Timeline

  • Jan 26, 2017 CVE Published
  • Oct 2, 2020 PoC Published
  • Nov 6, 2020 PoC Published
  • Apr 14, 2021 EPSS Score
  • Sep 6, 2021 PoC Published
  • Mar 7, 2023 EPSS Score
  • Sep 16, 2024 CVE Updated
  • Oct 9, 2024 PoC Published
  • Dec 12, 2024 PoC Published
  • Mar 17, 2025 EPSS Score
  • Mar 21, 2025 EPSS Score
  • Mar 22, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›