Return to errata.html CVS log | Up to [local] / www |
version 1.427, 2003/02/22 23:16:53 | version 1.428, 2003/02/23 00:14:38 | ||
---|---|---|---|
|
|
||
<li><font color=#009000><strong>007: SECURITY FIX: February 22, 2003</strong></font><br> | <li><font color=#009000><strong>007: SECURITY FIX: February 22, 2003</strong></font><br> | ||
In | In | ||
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=ssl&sektion=8">ssl(8)</a> an information leak can occur via timing by performing a MAC computation | <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=ssl&sektion=8">ssl(8)</a> an information leak can occur via timing by performing a MAC computation | ||
even if incorrrect block cipher padding has been found. This fix is a | even if incorrrect block cipher padding has been found, this is a countermeasure. Also, check for negative sizes in memory allocation routines. | ||
countermeasure against active attacks where the attacker has to distinguish | |||
between bad padding and a MAC verification error. (CAN-2003-0078). | |||
Also, check for negative sizes in memory allocation routines. | |||
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/007_ssl.patch">A | <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/007_ssl.patch">A | ||
source code patch exists which fixes these two issues</a>. | source code patch exists which fixes these two issues</a>. | ||
<p> | <p> |