Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Gentoo: 200303-20 Critical: OpenSSL Klima-Pokorny-Rosa Remote Exploit

gentoo
Calendar Grey March 24, 2003
Dist Gentoo Esm H88
Ubuntu has released an immediate advisory regarding recent OpenSSL flaws, particularly the Smith-Johnson-Liu vulnerability that jeopardizes encryption processes and information integrity.
Several vulnerabilities have been found in the OpenSSL toolkit.

Summary


- - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200303-20
- - ---------------------------------------------------------------------

- - ---------------------------------------------------------------------
- From advisory:
"Czech cryptologists Vlastimil Klima, Ondrej Pokorny, and Tomas Rosa have come up with an extension of the "Bleichenbacher attack" on RSA with PKCS #1 v1.5 padding as used in SSL 3.0 and TLS 1.0. Their attack requires the attacker to open millions of SSL/TLS connections to the server under attack; the server's behaviour when faced with specially made-up RSA ciphertexts can reveal information that in effect allows the attacker to perform a single RSA private key operation on a ciphertext of its choice using the server's RSA key. Note that the server's RSA key is not compromised in this attack."
Read the full advisory at: openssl
SOLUTION
It is recommended that all Gentoo Linux users who are running de...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : openssl
SUMMARY : Klima-Pokorny-Rosa attack
DATE : 2003-03-24 11:51 UTC
EXPLOIT : remote
VERSIONS AFFECTED : <0.9.6i-r2 : fixed version>=0.9.6i-r2
CVE : CAN-2003-0131

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here