Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Gentoo: 200303-24 Critical: Stunnel Remote Timing Attack Solution

gentoo
Calendar Grey March 25, 2003
Dist Gentoo Esm H88
Ubuntu addresses an internal privilege escalation flaw in OpenSSH, providing upgrade solutions for users to protect their SSH configurations.
Researchers have discovered a timing attack on RSA keys, to whichOpenSSL is generally vulnerable, unless RSA blinding has been turnedon.

Summary


- ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200303-24
- ---------------------------------------------------------------------
    FIXED VERSION : >=3.22-r2 (unstable: >=4.04)

- ---------------------------------------------------------------------
>From advisory:
"Researchers have discovered a timing attack on RSA keys, to which OpenSSL is generally vulnerable, unless RSA blinding has been turned on."
Read the full advisory at

SOLUTION
It is recommended that all Gentoo Linux users who are running net-misc/stunnel upgrade to stunnel-3.22-r2 (unstable: stunnel-4.04) as follows:
emerge sync emerge stunnel emerge clean


Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : stunnel
SUMMARY : timing based attack
DATE : 2003-03-25 17:55 UTC
EXPLOIT : remote
VERSIONS AFFECTED : <3.22-r2 (unstable: <4.04)
CVE : CAN-2003-0147

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here