Full Disclosure mailing list archives
Re: [ADVISORY] Timing Attack on OpenSSL
From: Jeffrey Altman <jaltman () columbia edu>
Date: Mon, 17 Mar 2003 08:06:45 -0800
This is a different vulnerability. The one you patched two weeks ago was caused by a failure to decrypt messages when the MAC comparison failed. This vulnerability is a timing attack against the RSA algorithms.
The Slashdot discussion is here: http://slashdot.org/article.pl?sid=03/03/14/0012214&mode=thread&tid=172 The paper is here: http://crypto.stanford.edu/~dabo/abstracts/ssl-timing.html Christopher Fowler wrote:
Is this a new advisory. I've patched for a previous timing attack 2 weeks ago.
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- [ADVISORY] Timing Attack on OpenSSL Ben Laurie (Mar 17)
- Re: [ADVISORY] Timing Attack on OpenSSL Christopher Fowler (Mar 17)
- Re: [ADVISORY] Timing Attack on OpenSSL Jeffrey Altman (Mar 17)
- Re: [ADVISORY] Timing Attack on OpenSSL Christopher Fowler (Mar 17)