VulnerabilityModified
CVE-2015-8618
The Int.Exp Montgomery code in the math/big library in Go 1.5.x before 1.5.3 mishandles carry propagation and produces incorrect output, which makes it easier for attackers to obtain private RSA keys via unspecified vectors.
HIGH 7.5EPSS 2.63%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Int.Exp Montgomery code in the math/big library in Go 1.5.x before 1.5.3 mishandles carry propagation and produces incorrect output, which makes it easier for attackers to obtain private RSA keys via unspecified vectors.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.63% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- opensuse/leap · golang/go
- Source
- cve@mitre.org
References
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175642.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176179.html
- http://lists.opensuse.org/opensuse-updates/2016-05/msg00077.html
- http://www.openwall.com/lists/oss-security/2015/12/21/6
- http://www.openwall.com/lists/oss-security/2015/12/22/9
- http://www.openwall.com/lists/oss-security/2016/01/13/7
- https://github.com/golang/go/issues/13515Patch
- https://go-review.googlesource.com/#/c/17672/
- https://groups.google.com/forum/#%21topic/golang-announce/MEATuOi_ei4
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175642.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176179.html
- http://lists.opensuse.org/opensuse-updates/2016-05/msg00077.html
- http://www.openwall.com/lists/oss-security/2015/12/21/6
- http://www.openwall.com/lists/oss-security/2015/12/22/9
- http://www.openwall.com/lists/oss-security/2016/01/13/7
- https://github.com/golang/go/issues/13515Patch
- https://go-review.googlesource.com/#/c/17672/
- https://groups.google.com/forum/#%21topic/golang-announce/MEATuOi_ei4
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.