A AegiFlow
MEDIUMCVSS 5.9

CVE-2015-7744

CVE-2015-7744 updated by NVD

Modified
2026-09-20
Sources
nvd

Summary

wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.

Affected packages

EcosystemPackageAffected versionsFixed versions
MariaDBmariadb[object Object], [object Object], [object Object]

References

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.