Vulnerability Bulletins

AIX OpenSSL does not properly calculate the square of a BIGNUM value which makes it easier for attacker to defeat cryptographic protection mechanisms

   
Affected software IBM
 
Unknown CVE(s): CVE-2014-3570, CVE-2014-3571, CVE-2014-3572, CVE-2014-8275, CVE-2015-0204, CVE-2015-0205 and CVE-2015-0206 Affected product(s) and affected version(s): Refer to the following reference URLs for remediation and additional vulnerability details: Source Bulletin: http://aix.software.ibm.com/aix/efixes/security/openssl_advisory12.asc X-Force Database: http://xforce.iss.net/xforce/xfdb/99710 X-Force Database: http://xforce.iss.net/xforce/xfdb/99703 X-Force Database:

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/aix_openssl_does_not_properly_calculate_the_square_of_a_bignum_value_which_makes_it_easier_for_attacker_to_defeat_cryptographic_protection_mechanisms?lang=en_us