VDB
GCVE-VVD-MAGEIA-2017-42
GCVE-VVD-MAGEIA-2017-42
Advisory Published
There is a carry propagation bug in the Broadwell-specific Montgomery
multiplication procedure that handles input lengths divisible by, but
longer than 256 bits. mong EC algorithms only Brainpool P-512 curves are
affected and one presumably can attack ECDH key negotiation
(CVE-2016-7055).
If an SSL/TLS server or client is running on a 32-bit host, and a specific
cipher is being used, then a truncated packet can cause that server or
client to perform an out-of-bounds read, usually resulting in a crash. The
crash can be triggered when using RC4-MD5, if it has not been disabled
(CVE-2017-3731).
There is a carry propagating bug in the x86_64 Montgomery squaring
procedure. An attacker would need online access to an unpatched system
using the target private key in a scenario with persistent DH parameters
and a private key that is shared between multiple clients (CVE-2017-3732).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | 0ad-data | 0 (affected), 0.0.22-1.mga6 (unaffected) | — |
| Mageia | openssl | 0 (affected), 1.0.2k-1.mga5 (unaffected), 0 (affected), 1.0.2k-1.mga5 (unaffected) | — |
| Mageia | 0ad | 0 (affected), 0.0.22-1.1.mga6 (unaffected) | — |
Aliases
Transitive aliases
H1-201346BDU:2020-02969CVE-2016-7053BDU:2020-02907CVE-2016-7054GHSA-rq64-8m54-26j4GHSA-3rqr-v2gc-jxp4cisco-sa-20170130-opensslCVE-2017-10408BDU:2020-02906EUVD-2017-2075EUVD-2017-2054VVD-CISA-2017-3637CVE-2017-2730CVE-2017-3730GHSA-cxwv-w4cv-77wpWID-SEC-W-2022-1914EUVD-2017-12849CVE-2017-10392EUVD-2017-2055GSD-2017-3733CNVD-2017-03330CNVD-2016-11095EUVD-2017-2039GHSA-hp2v-mmp5-5mcxCVE-2017-3733EUVD-2017-12850CNVD-2017-01958CVE-2017-3637GHSA-6j5f-6mxg-2mp9VVD-CISA-2017-10428VVD-CISA-2017-10392EUVD-2016-7935GHSA-cm48-4cv7-p665GHSA-wgw9-hgw6-6jgcGHSA-hxpw-pxmm-q49rGSD-2016-7053BDU:2020-02910VVD-CISA-2017-10407EUVD-2017-12754WID-SEC-W-2024-0208EUVD-2016-7933EUVD-2016-7934CVE-2017-10428GHSA-6553-6v42-5wqcGSD-2017-2730CNVD-2017-02334GHSA-5hg3-8gvm-5294VVD-MAGEIA-2017-390VVD-CISA-2017-10408EUVD-2017-11873GSD-2017-3730GHSA-4p8f-59q4-ww8gVVD-GENTOO-2017-625626cisco-sa-20161114-opensslGHSA-544p-f4g7-j9whEUVD-2017-12847BDU:2020-02908CVE-2017-10407BDU:2020-02911
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.