GLSA: openssl (200303-20)

From: Daniel Ahlberg (alizat_private)
Date: Mon Mar 24 2003 - 03:51:18 PST

  • Next message: Thomas Biege: "SuSE Security Announcement: mutt (SuSE-SA:2003:020)"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - - ---------------------------------------------------------------------
    GENTOO LINUX SECURITY ANNOUNCEMENT 200303-20
    - - ---------------------------------------------------------------------
    
              PACKAGE : openssl
              SUMMARY : Klima-Pokorny-Rosa attack
                 DATE : 2003-03-24 11:51 UTC
              EXPLOIT : remote
    VERSIONS AFFECTED : <0.9.6i-r2
        FIXED VERSION : >=0.9.6i-r2
                  CVE : CAN-2003-0131
    
    - - ---------------------------------------------------------------------
    
    - From advisory:
    
    "Czech cryptologists Vlastimil Klima, Ondrej Pokorny, and Tomas Rosa
    have come up with an extension of the "Bleichenbacher attack" on RSA
    with PKCS #1 v1.5 padding as used in SSL 3.0 and TLS 1.0.  Their
    attack requires the attacker to open millions of SSL/TLS connections
    to the server under attack; the server's behaviour when faced with
    specially made-up RSA ciphertexts can reveal information that in
    effect allows the attacker to perform a single RSA private key
    operation on a ciphertext of its choice using the server's RSA key.
    Note that the server's RSA key is not compromised in this attack."
    
    Read the full advisory at:
    http://www.openssl.org/news/secadv_20030319.txt
    
    SOLUTION
    
    It is recommended that all Gentoo Linux users who are running
    dev-libs/openssl upgrade to openssl-0.9.6i-r2 as follows:
    
    emerge sync
    emerge openssl
    emerge clean
    
    - - ---------------------------------------------------------------------
    alizat_private - GnuPG key is available at http://cvs.gentoo.org/~aliz
    - - ---------------------------------------------------------------------
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.1 (GNU/Linux)
    
    iD8DBQE+fvEtfT7nyhUpoZMRAjGBAJ9fkr/E5rMWv7Sp1YBg+3rRNqbS6wCglHh8
    XW2wBWHA0/W3NXOz+ONEFTg=
    =l0Nr
    -----END PGP SIGNATURE-----
    



    This archive was generated by hypermail 2b30 : Mon Mar 24 2003 - 09:24:28 PST