VYPR
Medium severity4.9OSV Advisory· Published Jun 15, 2018· Updated Jun 5, 2026

CVE-2018-12437

CVE-2018-12437

Description

LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Libtom/LibtomcryptOSV3 versions
    0.75, 0.76, 0.77, …+ 2 more
    • (no CPE)range: 0.75, 0.76, 0.77, …
    • cpe:2.3:a:libtom:libtomcrypt:*:*:*:*:*:*:*:*range: <=1.18.1
    • (no CPE)range: <=1.18.1
  • cpe:2.3:o:trustedfirmware:op-tee:*:*:*:*:*:*:*:*
    Range: <=3.5.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.