mailing list archives
Re: [ADVISORY] Timing Attack on OpenSSL
From: Jeffrey Altman <jaltman () columbia edu>
Date: Mon, 17 Mar 2003 08:06:45 -0800
This is a different vulnerability. The one you patched two weeks ago
was caused by a failure to decrypt messages when the MAC comparison
failed. This vulnerability is a timing attack against the RSA algorithms.
The Slashdot discussion is here:
The paper is here:
Christopher Fowler wrote:
Is this a new advisory. I've patched for a previous timing attack 2
Full-Disclosure - We believe in it.