Bug 960151 (CVE-2015-8618) - VUL-1: CVE-2015-8618: go: Carry propagation in Int.Exp Montgomery code in math/big library
Summary: VUL-1: CVE-2015-8618: go: Carry propagation in Int.Exp Montgomery code in mat...
Status: RESOLVED DUPLICATE of bug 968949
Alias: CVE-2015-8618
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Minor
Target Milestone: unspecified
Assignee: Jordi Massaguer
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/160034/
Whiteboard: CVSSv2:RedHat:CVE-2015-8618:2.6:(AV:N...
Keywords:
Depends on:
Blocks:
 
Reported: 2015-12-23 10:04 UTC by Andreas Stieger
Modified: 2019-05-07 10:57 UTC (History)
8 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2015-12-23 10:04:29 UTC
via rh#1293448

Carry propagation in Int.Exp Montgomery function was found in golang's math/big library, similar to CVE-2015-3193. This issue was introduced in the 1.5 release and remains present in 1.5.1 and 1.5.2.

https://github.com/golang/go/commit/4306352182bf94f86f0cfc6a8b0ed461cbf1d82c

CVE request:
http://seclists.org/oss-sec/2015/q4/550


References:
https://bugzilla.redhat.com/show_bug.cgi?id=1293448
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8618
http://seclists.org/oss-sec/2015/q4/564
Comment 1 Andreas Stieger 2015-12-23 10:06:50 UTC
go 1.5 (1.5.1, 1.5.2)
Affects openSUSE Tumbleweed only.
Does not affect SLE.
Does not affect openSUSE stable releases.

Assign to community maintainer.
Comment 3 Andreas Stieger 2016-01-16 21:24:59 UTC
https://groups.google.com/forum/#!topic/golang-announce/MEATuOi_ei4

"TLS servers on 32-bit systems could plausibly leak their RSA private key due to this issue."

"On 64-bit systems, the frequency of the bug is so low (less than one in 2^50) that it would be very difficult to exploit. Nonetheless, everyone is strongly encouraged to upgrade."
Comment 9 Flavio Castelli 2016-02-15 07:40:52 UTC
Reassigning the bug to Jordi, who is working on pushing out the update.

@Jordi can you close the bug as soon as all our packages have been released by maintenance?
Comment 10 Jordi Massaguer 2016-03-02 17:19:03 UTC
There is another bug for updating go to 1.5, which will update to the latest version (1.5.3), which includes this fix. I am marking it as a duplicate of this one.

*** This bug has been marked as a duplicate of bug 968949 ***
Comment 11 Bernhard Wiedemann 2016-05-04 09:00:30 UTC
This is an autogenerated message for OBS integration:
This bug (960151) was mentioned in
https://build.opensuse.org/request/show/393533 42.1 / go
Comment 12 Swamp Workflow Management 2016-05-18 12:14:01 UTC
openSUSE-SU-2016:1331-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 960151,974232
CVE References: CVE-2015-8618,CVE-2016-3959
Sources used:
openSUSE Leap 42.1 (src):    go-1.6.1-14.1
Comment 13 Swamp Workflow Management 2018-05-17 17:01:34 UTC
This is an autogenerated message for OBS integration:
This bug (960151) was mentioned in
https://build.opensuse.org/request/show/610123 Factory / go1.10
Comment 21 Swamp Workflow Management 2018-12-15 08:42:11 UTC
This is an autogenerated message for OBS integration:
This bug (960151) was mentioned in
https://build.opensuse.org/request/show/658307 Factory / go1.10
https://build.opensuse.org/request/show/658308 Factory / go1.11
Comment 23 Swamp Workflow Management 2018-12-17 15:43:41 UTC
This is an autogenerated message for OBS integration:
This bug (960151) was mentioned in
https://build.opensuse.org/request/show/658934 15.0+42.3 / go1.11
Comment 24 Swamp Workflow Management 2019-02-27 11:02:38 UTC
This is an autogenerated message for OBS integration:
This bug (960151) was mentioned in
https://build.opensuse.org/request/show/679777 Factory / go1.11
Comment 25 Swamp Workflow Management 2019-03-25 11:13:11 UTC
This is an autogenerated message for OBS integration:
This bug (960151) was mentioned in
https://build.opensuse.org/request/show/688187 Factory / go1.12