Lucene search

K
f5F5F5:K64009378
HistoryJan 29, 2016 - 12:00 a.m.

K64009378 : OpenSSL vulnerability CVE-2016-0701

2016-01-2900:00:00
my.f5.com
17

5.6 Medium

AI Score

Confidence

High

0.119 Low

EPSS

Percentile

95.4%

Security Advisory Description

The DH_check_pub_key function in crypto/dh/dh_check.c in OpenSSL 1.0.2 before 1.0.2f does not ensure that prime numbers are appropriate for Diffie-Hellman (DH) key exchange, which makes it easier for remote attackers to discover a private DH exponent by making multiple handshakes with a peer that chose an inappropriate number, as demonstrated by a number in an X9.42 file. (CVE-2016-0701)
Impact
None. F5 products are not affected by this vulnerability.