---
title: "CVE-2011-1945\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2011-1945?format=md
keywords: index, follow
---

# CVE-2011-1945

Publication date 31 May 2011

Last updated 24 July 2024

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The elliptic curve cryptography (ECC) subsystem in OpenSSL 1.0.0d and
earlier, when the Elliptic Curve Digital Signature Algorithm (ECDSA) is
used for the ECDHE\_ECDSA cipher suite, does not properly implement curves
over binary fields, which makes it easier for context-dependent attackers
to determine private keys via a timing attack and a lattice calculation.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2011-1945?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| openssl | 11.10 oneiric | Fixed 1.0.0e-2ubuntu1 |
| 11.04 natty | Fixed 0.9.8o-5ubuntu1.2 |
| 10.10 maverick | Fixed 0.9.8o-1ubuntu4.6 |
| 10.04 LTS lucid | Fixed 0.9.8k-7ubuntu8.8 |
| 8.04 LTS hardy | Fixed 0.9.8g-4ubuntu3.15 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2011-1945?format=md#patch-details)

## Notes

---

### [jdstrand](https://launchpad.net/~jdstrand)

from upstream: "The OpenSSL team have reviewed the paper, and
although the result is significant, we believe that the affected code (ECDSA
used with binary curves) is very rarely used at present. We therefore do not
plan on issuing a security release but expect to patch this in the future."

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| openssl | * Upstream:   <http://marc.info/?l=openssl-cvs&m=130633562421834&w=2> * Upstream:   <http://marc.info/?l=openssl-cvs&m=131488703100302&w=2> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1945)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2011-1945)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2011-1945)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2011-1945)

### Related Ubuntu Security Notices (USN)

+ [USN-1357-1](https://usn.ubuntu.com/USN-1357-1)
+ OpenSSL vulnerabilities
+ 9 February 2012

### Other references

* <http://www.kb.cert.org/vuls/id/MAPG-8FENZ3>
* <http://www.kb.cert.org/vuls/id/536044>
* <https://www.cve.org/CVERecord?id=CVE-2011-1945>
