Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

patches available for RSA timing attacks

From: Todd C. Miller <Todd.Miller(at)courtesan.com>
Date: Wed Mar 19 2003 - 18:42:11 EST


Researchers have discovered a timing attack on RSA keys to which OpenSSL is vulnerable. OpenBSD patches are now available. The following paper describes the attack in detail:

    http://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf

The patches have already been committed to OpenBSD-current and the 3.1 and 3.2 -stable branches. For those who wish to manually patch their systems, the following patches are available.

Patch for OpenBSD 3.1:

    ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/024_blinding.patch

Patch for OpenBSD 3.2:

    ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/011_blinding.patch

The OpenSSL advisory (from which the patches are derived) is:

Do you need help?X

    http://www.openssl.org/news/secadv_20030317.txt Received on Wed Mar 19 18:44:44 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:46:07 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library