Home page logo

fulldisclosure logo Full Disclosure mailing list archives

Re: [ADVISORY] Timing Attack on OpenSSL
From: Jeffrey Altman <jaltman () columbia edu>
Date: Mon, 17 Mar 2003 08:06:45 -0800

This is a different vulnerability. The one you patched two weeks ago was caused by a failure to decrypt messages when the MAC comparison failed. This vulnerability is a timing attack against the RSA algorithms.

The Slashdot discussion is here:


The paper is here:


Christopher Fowler wrote:

Is this a new advisory.  I've patched for a previous timing attack 2
weeks ago.

Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]