OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[Full-Disclosure] Re: [ADVISORY] Timing Attack on OpenSSL

From: Jeffrey Altman (jaltmancolumbia.edu)
Date: Mon Mar 17 2003 - 10:06:45 CST


This is a different vulnerability. The one you patched two weeks ago
was caused by a failure to decrypt messages when the MAC comparison
failed. This vulnerability is a timing attack against the RSA algorithms.

The Slashdot discussion is here:

  http://slashdot.org/article.pl?sid=03/03/14/0012214&mode=thread&tid=172

The paper is here:

  http://crypto.stanford.edu/~dabo/abstracts/ssl-timing.html

Christopher Fowler wrote:

>Is this a new advisory. I've patched for a previous timing attack 2
>weeks ago.
>

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html