- - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200303-23
- - ---------------------------------------------------------------------

          PACKAGE : mod_ssl
          SUMMARY : timing based attack
             DATE : 2003-03-25 10:14 UTC
          EXPLOIT : remote
VERSIONS AFFECTED : <2.8.14 : fixed version>=2.8.14
              CVE : CAN-2003-0147

- - ---------------------------------------------------------------------

- From advisory:

"Researchers have discovered a timing attack on RSA keys, to which
OpenSSL is generally vulnerable, unless RSA blinding has been turned
on."

Read the full advisory at 
openssl

SOLUTION

It is recommended that all Gentoo Linux users who are running
net-www/mod_ssl upgrade to mod_ssl-2.8.14 as follows:

emerge sync
emerge mod_ssl
emerge clean

- - ---------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at   
- - ---------------------------------------------------------------------

2.8.14

Gentoo: mod_ssl timing based attack vulnerability

Researchers have discovered a timing attack on RSA keys, to which OpenSSL is generally vulnerable, unless RSA blinding has been turned on.

Summary


- - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200303-23
- - ---------------------------------------------------------------------

- - ---------------------------------------------------------------------
- From advisory:
"Researchers have discovered a timing attack on RSA keys, to which OpenSSL is generally vulnerable, unless RSA blinding has been turned on."
Read the full advisory at openssl
SOLUTION
It is recommended that all Gentoo Linux users who are running net-www/mod_ssl upgrade to mod_ssl-2.8.14 as follows:
emerge sync emerge mod_ssl emerge clean
- - --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at - - ---------------------------------------------------------------------
2.8.14

Resolution

References

Availability

Concerns

Severity
PACKAGE : mod_ssl
SUMMARY : timing based attack
DATE : 2003-03-25 10:14 UTC
EXPLOIT : remote
VERSIONS AFFECTED : <2.8.14 : fixed version>=2.8.14
CVE : CAN-2003-0147

Synopsis

Background

Affected Packages

Impact

Workaround

Related News