← Vulnerability feed

Vulnerability record · CVE-2018-12437 · published 15 June 2018

CVE-2018-12437: Libtomcrypt information exposure vulnerability

Libtom · Libtomcrypt

LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

4.9 CVSS 3.1 Medium EPSS 0.54% · top 56.3% CWE-200 · Information exposure
4.9CVSS 3.1 base score, v2 1.9
0.54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-12437 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-1010292Trustedfirmware op-tee out-of-bounds write vulnerabilityLinaro/OP-TEE OP-TEE Prior to version v3.4.0 is affected by: Boundary checks. The impact is: This could lead to corruption of any memory which the TA…EPSS 1.6%9.8CVE-2019-1010296Trustedfirmware op-tee integer overflow vulnerabilityLinaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in context of TEE core (kernel). The component …EPSS 2.8%9.8CVE-2019-1010297Trustedfirmware op-tee integer overflow vulnerabilityLinaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Execution of code in TEE core (kernel) context. The component …EPSS 2.7%9.8CVE-2019-1010295Trustedfirmware op-tee improper input validation vulnerabilityLinaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Memory corruption and disclosure of memory content. The compon…EPSS 1.6%9.8CVE-2019-1010293Trustedfirmware op-tee out-of-bounds write vulnerabilityLinaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Boundary crossing. The impact is: Memory corruption of the TEE itself. The component is: optee…EPSS 1.6%9.8CVE-2019-1010298Trustedfirmware op-tee integer overflow vulnerabilityLinaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in the context of TEE core (kernel). The compon…EPSS 3.9%9.1CVE-2019-25052Trustedfirmware op-tee broken cryptographic algorithm vulnerabilityIn Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptographic functions directly, cau…EPSS 0.87%9.1CVE-2019-17362Libtomcrypt out-of-bounds read vulnerabilityIn LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 seque…EPSS 3.1%

Source: NIST National Vulnerability Database (record CVE-2018-12437), CISA KEV, FIRST EPSS (scores of 2026-10-09). This page is refreshed as NVD updates the record.