version 1.436, 2003/03/19 01:47:10 |
version 1.437, 2003/03/19 23:48:01 |
|
|
<a name=all></a> |
<a name=all></a> |
<li><h3><font color="#e00000">All architectures</font></h3> |
<li><h3><font color="#e00000">All architectures</font></h3> |
<ul> |
<ul> |
|
<a name=kpr></a> |
|
<li><font color="#009000"><strong>012: SECURITY FIX: March 19, 2003</strong></font><br> |
|
OpenSSL is vulnerable to an extension of the ``Bleichenbacher'' attach designed |
|
by Czech researchers Klima, Pokorny and Rosa. |
|
<br> |
|
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/012_kpr.patch">A |
|
source code patch exists which remedies the problem</a>. |
|
<p> |
<a name=blinding></a> |
<a name=blinding></a> |
<li><font color="#009000"><strong>011: SECURITY FIX: March 18, 2003</strong></font><br> |
<li><font color="#009000"><strong>011: SECURITY FIX: March 18, 2003</strong></font><br> |
Various SSL and TLS operations in OpenSSL are vulnerable to timing attacks. |
Various SSL and TLS operations in OpenSSL are vulnerable to timing attacks. |