CVE-2003-0131
CVE-2003-0131
The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the "Klima-Pokorny-Rosa attack."
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-007.txt.ascftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txtftp://patches.sgi.com/support/free/security/advisories/20030501-01-Ihttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000625http://eprint.iacr.org/2003/052/http://lists.apple.com/mhonarc/security-announce/msg00028.htmlhttp://marc.info/?l=bugtraq&m=104811162730834&w=2http://marc.info/?l=bugtraq&m=104852637112330&w=2http://marc.info/?l=bugtraq&m=104878215721135&w=2https://exchange.xforce.ibmcloud.com/vulnerabilities/11586https://lists.opensuse.org/opensuse-security-announce/2003-04/msg00005.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A461