CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Factoring RSA Keys with Many Zeros

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 417

As cited

Copy frozen at (site build).

research

Factoring RSA Keys with Many Zeros

Researchers discovered a new class of weak RSA keys characterized by regularly spaced blocks of zeros in their moduli, found in real-world deployments including expired certificates for Yahoo and Verizon, and SSH hosts running CompleteFTP software. The CompleteFTP vulnerability affects RSA keys generated in versions 10.0.0 through 12.0.0 and DSA keys up to version 23.0.4, with cryptanalytic algorithms potentially tailored to exploit this specific weakness. The findings suggest independent implementations failed similarly, raising questions about whether additional cryptographic products contain comparable flaws.

Why it matters: If you manage keys or certificates from affected vendors (especially older CompleteFTP deployments), verify your RSA implementations are not generating sparse moduli that could be factored.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary