CVE-2010-0928

Source
https://cve.org/CVERecord?id=CVE-2010-0928
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2010-0928.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2010-0928
Withdrawn
2024-06-05T12:44:47.682578Z
Published
2010-03-05T19:30:00Z
Modified
2024-06-04T04:54:51.642971Z
Summary
[none]
Details

OpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation (FWE) algorithm for certain signature calculations, and does not verify the signature before providing it to a caller, which makes it easier for physically proximate attackers to determine the private key via a modified supply voltage for the microprocessor, related to a "fault-based attack."

References

Affected packages

Debian:10 / openssl

Package

Name
openssl
Purl
pkg:deb/debian/openssl?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.1.1c-1
1.1.1d-0+deb10u1
1.1.1d-0+deb10u2
1.1.1d-0+deb10u3
1.1.1d-0+deb10u4
1.1.1d-0+deb10u5
1.1.1d-0+deb10u6
1.1.1d-0+deb10u7
1.1.1d-0+deb10u8
1.1.1d-1
1.1.1d-2
1.1.1e-1
1.1.1f-1
1.1.1g-1
1.1.1h-1
1.1.1i-1
1.1.1i-2
1.1.1i-3
1.1.1j-1
1.1.1k-1
1.1.1l-1
1.1.1m-1
1.1.1n-0+deb10u1
1.1.1n-0+deb10u2
1.1.1n-0+deb10u3
1.1.1n-0+deb10u4
1.1.1n-0+deb10u5
1.1.1n-0+deb10u6
1.1.1n-1
1.1.1o-1
1.1.1v-0~deb11u1
1.1.1w-0~deb11u1
3.*
3.0.0~~alpha1-1
3.0.0~~alpha3-1
3.0.0~~alpha4-1
3.0.0~~alpha13-1
3.0.0~~alpha13-2
3.0.0~~alpha15-1
3.0.0~~alpha16-1
3.0.0~~beta1-1
3.0.0~~beta2-1
3.0.0-1
3.0.1-1
3.0.2-1
3.0.3-1
3.0.3-2
3.0.3-2+ia64
3.0.3-3
3.0.3-4
3.0.3-5
3.0.3-6
3.0.3-7
3.0.3-8
3.0.4-1
3.0.4-2
3.0.5-1
3.0.5-2
3.0.5-3
3.0.5-4
3.0.7-1
3.0.7-2
3.0.8-1
3.0.9-1
3.0.10-1~deb12u1
3.0.10-1
3.0.11-1~deb12u1
3.0.11-1~deb12u2
3.0.11-1
3.0.12-1
3.0.12-2
3.0.13-1~deb12u1
3.1.0-1
3.1.1-1
3.1.2-1
3.1.3-1
3.1.4-1
3.1.4-2
3.1.5-1
3.1.5-1.1
3.2.0-1
3.2.0-2
3.2.1-1
3.2.1-1.1~exp1
3.2.1-2
3.2.1-3
3.3.0~beta1-1
3.3.0-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2010-0928.json"

Debian:11 / openssl

Package

Name
openssl
Purl
pkg:deb/debian/openssl?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.1.1k-1
1.1.1k-1+deb11u1
1.1.1k-1+deb11u2
1.1.1l-1
1.1.1m-0+deb11u1
1.1.1m-1
1.1.1n-0+deb11u1
1.1.1n-0+deb11u2
1.1.1n-0+deb11u3
1.1.1n-0+deb11u4
1.1.1n-0+deb11u5
1.1.1n-1
1.1.1o-1
1.1.1v-0~deb11u1
1.1.1w-0~deb11u1
1.1.1w-0+deb11u1
3.*
3.0.0~~alpha1-1
3.0.0~~alpha3-1
3.0.0~~alpha4-1
3.0.0~~alpha13-1
3.0.0~~alpha13-2
3.0.0~~alpha15-1
3.0.0~~alpha16-1
3.0.0~~beta1-1
3.0.0~~beta2-1
3.0.0-1
3.0.1-1
3.0.2-1
3.0.3-1
3.0.3-2
3.0.3-2+ia64
3.0.3-3
3.0.3-4
3.0.3-5
3.0.3-6
3.0.3-7
3.0.3-8
3.0.4-1
3.0.4-2
3.0.5-1
3.0.5-2
3.0.5-3
3.0.5-4
3.0.7-1
3.0.7-2
3.0.8-1
3.0.9-1
3.0.10-1~deb12u1
3.0.10-1
3.0.11-1~deb12u1
3.0.11-1~deb12u2
3.0.11-1
3.0.12-1
3.0.12-2
3.0.13-1~deb12u1
3.1.0-1
3.1.1-1
3.1.2-1
3.1.3-1
3.1.4-1
3.1.4-2
3.1.5-1
3.1.5-1.1
3.2.0-1
3.2.0-2
3.2.1-1
3.2.1-1.1~exp1
3.2.1-2
3.2.1-3
3.3.0~beta1-1
3.3.0-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2010-0928.json"

Debian:12 / openssl

Package

Name
openssl
Purl
pkg:deb/debian/openssl?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.0.9-1
3.0.10-1~deb12u1
3.0.10-1
3.0.11-1~deb12u1
3.0.11-1~deb12u2
3.0.11-1
3.0.12-1
3.0.12-2
3.0.13-1~deb12u1
3.1.0-1
3.1.1-1
3.1.2-1
3.1.3-1
3.1.4-1
3.1.4-2
3.1.5-1
3.1.5-1.1
3.2.0-1
3.2.0-2
3.2.1-1
3.2.1-1.1~exp1
3.2.1-2
3.2.1-3
3.3.0~beta1-1
3.3.0-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2010-0928.json"

Debian:13 / openssl

Package

Name
openssl
Purl
pkg:deb/debian/openssl?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.0.9-1
3.0.10-1~deb12u1
3.0.10-1
3.0.11-1~deb12u1
3.0.11-1~deb12u2
3.0.11-1
3.0.12-1
3.0.12-2
3.0.13-1~deb12u1
3.1.0-1
3.1.1-1
3.1.2-1
3.1.3-1
3.1.4-1
3.1.4-2
3.1.5-1
3.1.5-1.1
3.2.0-1
3.2.0-2
3.2.1-1
3.2.1-1.1~exp1
3.2.1-2
3.2.1-3
3.3.0~beta1-1
3.3.0-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2010-0928.json"