- ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200303-24
- ---------------------------------------------------------------------

          PACKAGE : stunnel
          SUMMARY : timing based attack
             DATE : 2003-03-25 17:55 UTC
          EXPLOIT : remote
VERSIONS AFFECTED : <3.22-r2 (unstable: <4.04)
    FIXED VERSION : >=3.22-r2 (unstable: >=4.04)
              CVE : CAN-2003-0147

- ---------------------------------------------------------------------

>From advisory:

"Researchers have discovered a timing attack on RSA keys, to which
OpenSSL is generally vulnerable, unless RSA blinding has been turned
on."

Read the full advisory at 


SOLUTION

It is recommended that all Gentoo Linux users who are running
net-misc/stunnel upgrade to stunnel-3.22-r2 (unstable: stunnel-4.04)
as follows:

emerge sync
emerge stunnel
emerge clean



Gentoo: stunnel Remote timing attack

Researchers have discovered a timing attack on RSA keys, to whichOpenSSL is generally vulnerable, unless RSA blinding has been turnedon.

Summary


- ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200303-24
- ---------------------------------------------------------------------
    FIXED VERSION : >=3.22-r2 (unstable: >=4.04)

- ---------------------------------------------------------------------
>From advisory:
"Researchers have discovered a timing attack on RSA keys, to which OpenSSL is generally vulnerable, unless RSA blinding has been turned on."
Read the full advisory at

SOLUTION
It is recommended that all Gentoo Linux users who are running net-misc/stunnel upgrade to stunnel-3.22-r2 (unstable: stunnel-4.04) as follows:
emerge sync emerge stunnel emerge clean


Resolution

References

Availability

Concerns

Severity
PACKAGE : stunnel
SUMMARY : timing based attack
DATE : 2003-03-25 17:55 UTC
EXPLOIT : remote
VERSIONS AFFECTED : <3.22-r2 (unstable: <4.04)
CVE : CAN-2003-0147

Synopsis

Background

Affected Packages

Impact

Workaround

Related News