LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 10-23-2017, 04:26 AM   #1
LittleMaster
Member
 
Registered: Jun 2012
Posts: 121
Blog Entries: 1

Rep: Reputation: Disabled
vulnerability (CVE-2017-15361) which has any potantial security threat for Redhat Server hosted on HP hardware


Hi Team,

Need a help whether any one has any insight about vulnerability (CVE-2017-15361) ...Whether it has any impact to REDHAT operating system hosted on HP hardware .

Since i'm unable to find enough information on Redhat/HP official support link about CVE -2017-15361 .

Found few article on sites .....Does any one has any insight about the vulnerability could be very helpful ..


The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 0000000000008521 - 133.33, mishandles RSA key generation, which makes it easier for attackers to defeat various cryptographic protection mechanisms via targeted attacks, aka ROCA. Examples of affected technologies include BitLocker with TPM 1.2, YubiKey 4 (before 4.3.5) PGP key generation, and the Cached User Data encryption feature in Chrome OS

https://packetstormsecurity.com/file...HF03789-2.html


https://crocs.fi.muni.cz/public/papers/rsa_ccs17


ROCA: Vulnerable RSA generation (CVE-2017-15361)

Last edited by LittleMaster; 10-23-2017 at 04:37 AM.
 
Old 10-27-2017, 02:36 PM   #2
MensaWater
LQ Guru
 
Registered: May 2005
Location: Atlanta Georgia USA
Distribution: Redhat (RHEL), CentOS, Fedora, CoreOS, Debian, FreeBSD, HP-UX, Solaris, SCO
Posts: 7,831
Blog Entries: 15

Rep: Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669
Failing to find any other info you might want to try the detection tools provided:
https://crocs.fi.muni.cz/public/pape...nd_workarounds

Note the CVE specifically mentions HP is affected. However it appears this is only a problem for devices designed to do their own security so I suspect it wouldn't affect RSA keys you generated with ssh-keygen on RedHat.

Last edited by MensaWater; 10-30-2017 at 09:22 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] CVE-2016-0800 - DROWN security vulnerability ilesterg Linux - Security 3 03-27-2016 02:15 AM
vulnerability scanning using NMAP on CVE-2014-0322 vulnerability,check vulnerable meeiyoke Linux - Security 2 06-06-2014 05:09 PM
vulnerability scanning using NMAP on CVE-2014-0322 vulnerability,check vulnerable . meeiyoke Linux - Newbie 1 06-06-2014 12:14 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 03:22 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration