crypto/rsa/rsa_gen.c in OpenSSL before 0.9.6 mishandles C...
High severity
Unreviewed
Published
Apr 30, 2022
to the GitHub Advisory Database
•
Updated Apr 12, 2025
Description
Published by the National Vulnerability Database
May 5, 2016
Published to the GitHub Advisory Database
Apr 30, 2022
Last updated
Apr 12, 2025
crypto/rsa/rsa_gen.c in OpenSSL before 0.9.6 mishandles C bitwise-shift operations that exceed the size of an expression, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging improper RSA key generation on 64-bit HP-UX platforms.
References